CVE-2019-13636
UnknownEPSS 3.93%
Last modified
CVE-2019-13636 is a vulnerability of currently unknown severity. In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.. EPSS estimates a 3.93% chance of exploitation in the next 30 days.
Description
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Patch | <= 2.7.6 |
References
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71aMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00016.htmlThird Party Advisory
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71aMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00016.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13636?
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
How severe is CVE-2019-13636?
Severity scoring for CVE-2019-13636 is pending analysis. The EPSS model estimates a 3.93% probability of exploitation in the next 30 days.
How do I fix CVE-2019-13636?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13628wolfSSL and wolfCrypt 4.0.0 and earlier (when configured wit…4.7
- CVE-2019-13629MatrixSSL 4.2.1 and earlier contains a timing side channel i…5.9
- CVE-2019-1363An information disclosure vulnerability exists in the way th…5.5
- CVE-2019-13631In parse_hid_report_descriptor in drivers/input/tablet/gtco.…
- CVE-2019-13633Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS.…6.1
- CVE-2019-13635The WP Fastest Cache plugin through 0.8.9.5 for WordPress al…
- CVE-2019-13637In LogMeIn join.me before 3.16.0.5505, an attacker could exe…
- CVE-2019-13638GNU patch through 2.7.6 is vulnerable to OS shell command in…
- CVE-2019-1364An elevation of privilege vulnerability exists in Windows wh…7.8
- CVE-2019-13640In qBittorrent before 4.1.7, the function Application::runEx…
- CVE-2019-13643Stored XSS in EspoCRM before 5.6.4 allows remote attackers t…
- CVE-2019-13644Firefly III before 4.7.17.1 is vulnerable to stored XSS due …5.4
Are you affected by CVE-2019-13636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
