Double Free in Patch - CVE-2018-6952

 

Double Free in Patch - CVE-2018-6952

Published: April 19, 2019


Vulnerability identifier: #VU18323
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6952
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing untrusted input within the another_hunk() function in pch.c. A remote attacker can create a specially crafted file, trick the victim into using in with the affected application, trigger a double free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Patch
Arch Linux
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Server
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Fedora
patch (Alpine package)
patch
patch-debuginfo
patch-debugsource

How to mitigate CVE-2018-6952

Install updates from vendor's repository.

patch (Alpine package) - update to 2.7.6-r0
patch - addressed in versions 2.7.5-8.8.1, 2.7.6-150000.5.3.1
patch-debuginfo - addressed in versions 2.7.5-8.8.1, 2.7.6-150000.5.3.1
patch-debugsource - addressed in versions 2.7.5-8.8.1, 2.7.6-150000.5.3.1
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27, 2.7.6-5.fc27, 2.7.6-5.fc28, 2.7.6-7.fc29

External References

Related Security Bulletins