OS Command Injection in Patch - CVE-2019-13638
Published: July 28, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient validation of ed style diff payload with shell metacharacters in patch files. A remote attacker can trick the victim to use a specially crafted patch file and execute arbitrary OS commands.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Fedora
patch (Alpine package)
patch (Debian package)
patch (Red Hat package)
patch
How to mitigate CVE-2019-13638
patch (Debian package) - update to 2.7.5-1+deb9u2
patch (Red Hat package) - update to 2.7.1-11.el7_6
patch - update to 2.7.6-11.fc30
External References
Related Security Bulletins
- Debian update for patch
- Gentoo update for Patch
- Red Hat update for patch
- Red Hat update for patch
- Amazon Linux AMI update for patch
- Red Hat update for patch
- Red Hat update for patch
- OS Command Injection in patch (Alpine package)
- Red Hat Enterprise Linux 7.6 Extended Update Support update for patch
- Fedora 30 update for patch