Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882870
Category:CentOS Local Security Checks
Title:CentOS Update for patch CESA-2018:1199 centos6
Summary:Check the version of patch
Description:Summary:
Check the version of patch

Vulnerability Insight:
The patch program applies diff files to
originals. The diff command is used to compare an original to a changed file.
Diff lists the changes made to the file. A person who has the original file
can then use the patch command with the diff file to add the changes to their
original file (patching the file).

Patch should be installed because it is a common way of upgrading
applications.

Security Fix(es):

* patch: Malicious patch files cause ed to execute arbitrary commands
(CVE-2018-1000156)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Affected Software/OS:
patch on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1000156
Bugtraq: 20190730 [SECURITY] [DSA 4489-1] patch security update (Google Search)
https://seclists.org/bugtraq/2019/Jul/54
Bugtraq: 20190816 Details about recent GNU patch vulnerabilities (Google Search)
https://seclists.org/bugtraq/2019/Aug/29
https://security.gentoo.org/glsa/201904-17
http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
http://rachelbythebay.com/w/2018/04/05/bangpatch/
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=894667#19
https://twitter.com/kurtseifried/status/982028968877436928
https://lists.debian.org/debian-lts-announce/2018/04/msg00013.html
RedHat Security Advisories: RHSA-2018:1199
https://access.redhat.com/errata/RHSA-2018:1199
RedHat Security Advisories: RHSA-2018:1200
https://access.redhat.com/errata/RHSA-2018:1200
RedHat Security Advisories: RHSA-2018:2091
https://access.redhat.com/errata/RHSA-2018:2091
RedHat Security Advisories: RHSA-2018:2092
https://access.redhat.com/errata/RHSA-2018:2092
RedHat Security Advisories: RHSA-2018:2093
https://access.redhat.com/errata/RHSA-2018:2093
RedHat Security Advisories: RHSA-2018:2094
https://access.redhat.com/errata/RHSA-2018:2094
RedHat Security Advisories: RHSA-2018:2095
https://access.redhat.com/errata/RHSA-2018:2095
RedHat Security Advisories: RHSA-2018:2096
https://access.redhat.com/errata/RHSA-2018:2096
RedHat Security Advisories: RHSA-2018:2097
https://access.redhat.com/errata/RHSA-2018:2097
https://usn.ubuntu.com/3624-1/
https://usn.ubuntu.com/3624-2/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.