Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.883119
Categoría:CentOS Local Security Checks
Título:CentOS Update for patch CESA-2019:2964 centos7
Resumen:The remote host is missing an update for the 'patch'; package(s) announced via the CESA-2019:2964 advisory.
Descripción:Summary:
The remote host is missing an update for the 'patch'
package(s) announced via the CESA-2019:2964 advisory.

Vulnerability Insight:
The patch program applies diff files to originals. The diff command is used
to compare an original to a changed file. Diff lists the changes made to
the file. A person who has the original file can then use the patch command
with the diff file to add the changes to their original file (patching the
file).

Security Fix(es):

* patch: do_ed_script in pch.c does not block strings beginning with a !
character (CVE-2018-20969)

* patch: OS shell command injection when processing crafted patch files
(CVE-2019-13638)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'patch' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-20969
Bugtraq: 20190816 Details about recent GNU patch vulnerabilities (Google Search)
https://seclists.org/bugtraq/2019/Aug/29
http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=3fcd042d26d70856e826a42b5f93dc4854d80bf0
https://github.com/irsl/gnu-patch-vulnerabilities
RedHat Security Advisories: RHSA-2019:2798
https://access.redhat.com/errata/RHSA-2019:2798
RedHat Security Advisories: RHSA-2019:2964
https://access.redhat.com/errata/RHSA-2019:2964
RedHat Security Advisories: RHSA-2019:3757
https://access.redhat.com/errata/RHSA-2019:3757
RedHat Security Advisories: RHSA-2019:3758
https://access.redhat.com/errata/RHSA-2019:3758
RedHat Security Advisories: RHSA-2019:4061
https://access.redhat.com/errata/RHSA-2019:4061
Common Vulnerability Exposure (CVE) ID: CVE-2019-13638
Bugtraq: 20190730 [SECURITY] [DSA 4489-1] patch security update (Google Search)
https://seclists.org/bugtraq/2019/Jul/54
Debian Security Information: DSA-4489 (Google Search)
https://www.debian.org/security/2019/dsa-4489
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT/
https://security.gentoo.org/glsa/201908-22
https://security-tracker.debian.org/tracker/CVE-2019-13638
CopyrightCopyright (C) 2019 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.