CVE-2018-6952
patch: Double free of memory in pch.c:another_hunk() causes a crash
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
Existe una doble liberación (double free) en la función another_hunk en pch.c en GNU patch hasta la versión 2.7.6.
A double-free flaw was found in the way the patch utility processed patch files. An attacker could potentially use this flaw to crash the patch utility by tricking it into processing crafted patches.
The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file. Issues addressed include an out of bounds access vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-13 CVE Reserved
- 2018-02-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
- CWE-416: Use After Free
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103047 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:2033 | 2019-04-17 | |
https://savannah.gnu.org/bugs/index.php?53133 | 2019-04-17 | |
https://security.gentoo.org/glsa/201904-17 | 2019-04-17 | |
https://access.redhat.com/security/cve/CVE-2018-6952 | 2019-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1545053 | 2019-08-06 |