NULL pointer dereference in Patch - CVE-2018-6951
Published: March 20, 2018
Vulnerability identifier: #VU11177
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6951
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the intuit_diff_type function due to NULL pointer dereference. A remote attacker can cause the service to crash.
The weakness exists in the intuit_diff_type function due to NULL pointer dereference. A remote attacker can cause the service to crash.
Affected software
Patch
Gentoo Linux
Arch Linux
SUSE Linux
Fedora
patch (Alpine package)
patch
Gentoo Linux
Arch Linux
SUSE Linux
Fedora
patch (Alpine package)
patch
How to mitigate CVE-2018-6951
Install update from vendor's website.
patch (Alpine package) - addressed in versions 2.7.5-r2, 2.7.6-r2
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27, 2.7.6-5.fc27, 2.7.6-5.fc28
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27, 2.7.6-5.fc27, 2.7.6-5.fc28
External References
Related Security Bulletins
- Denial of service in GNU patch
- SUSE Linux update for patch
- OpenSUSE Linux update for patch
- Gentoo update for Patch
- Arch Linux update for patch
- NULL pointer dereference in patch (Alpine package)
- Fedora 27 update for patch
- Fedora 26 update for patch
- Fedora 27 update for patch
- Fedora 28 update for patch