patch: directory traversal flaw allows for arbitrary file creation
Published Mar 11, 2011
5.8
MEDIUMCVSS 2.0
EPSS 4.87%
Description
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
patch
Will not fix
Red Hat Enterprise Linux 5
patch
Will not fix
Red Hat Enterprise Linux 6
patch
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | patch | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | patch | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | patch | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (18)
- http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1 x_refsource_CONFIRMPatch
- http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html vendor-advisoryx_refsource_FEDORAPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html vendor-advisoryx_refsource_FEDORAPatch
- http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2011/01/05/10 mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2011/01/06/19 mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2011/01/06/20 mailing-listx_refsource_MLIST
- http://openwall.com/lists/oss-security/2011/01/06/21 mailing-listx_refsource_MLISTPatch
- http://secunia.com/advisories/43663 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43677 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://support.apple.com/kb/HT4723 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/46768 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2011/0600 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-4651 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=667529 x_refsource_CONFIRMPatchIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-4651
- https://www.cve.org/CVERecord?id=CVE-2010-4651
Change history (0)
No recorded changes yet.