漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NULL Pointer Dereference in GNU patch
Vulnerability Description
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.
An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.
This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
空指针解引用
Vulnerability Title
GNU patch 异常处理不当漏洞
Vulnerability Description
GNU patch是美国GNU基金会开源的一个应用补丁修正程序。 GNU patch 2.8.0及之前版本存在异常处理不当漏洞,该漏洞源于处理特制的统一差异补丁文件时空指针取消引用,对连续文件结束换行标记处理不当可能破坏内部数据块数据结构,导致处理过程中向fwrite传递空指针,攻击者利用恶意补丁文件触发此条件,导致程序崩溃并拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A