« List of all CVEs

CVE-2019-13638

Published: 7/26/2019 Last updated: 8/4/2024 Reserved: 7/17/2019

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

rml

Products affected (1)

Product Vendor Version
n/a n/a 4.5.2 on Windows Server 2012 (Server Core installation)

References (30)