Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Patch 输入验证漏洞
Vulnerability Description
GNU Patch是GNU项目中的一套用于生成补丁文件的工具。 GNU Patch 2.7.6 版本中存在输入验证漏洞。远程攻击者可借助补丁文件利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A