CVE-2019-13638
Last modified
CVE-2019-13638 is a vulnerability of currently unknown severity. GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. EPSS estimates a 4.53% chance of exploitation in the next 30 days.
Description
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Patch | 2.7.6 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=3fcd042d26d70856e826a42b5f93dc4854d80bf0Mailing List, Patch, Vendor Advisory
- https://seclists.org/bugtraq/2019/Jul/54Mailing List, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2019-13638Third Party Advisory
- https://www.debian.org/security/2019/dsa-4489Third Party Advisory
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=3fcd042d26d70856e826a42b5f93dc4854d80bf0Mailing List, Patch, Vendor Advisory
- https://seclists.org/bugtraq/2019/Jul/54Mailing List, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2019-13638Third Party Advisory
- https://www.debian.org/security/2019/dsa-4489Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13638?
How severe is CVE-2019-13638?
How do I fix CVE-2019-13638?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1363An information disclosure vulnerability exists in the way th…5.5
- CVE-2019-13631In parse_hid_report_descriptor in drivers/input/tablet/gtco.…
- CVE-2019-13633Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS.…6.1
- CVE-2019-13635The WP Fastest Cache plugin through 0.8.9.5 for WordPress al…
- CVE-2019-13636In GNU patch through 2.7.6, the following of symlinks is mis…
- CVE-2019-13637In LogMeIn join.me before 3.16.0.5505, an attacker could exe…
- CVE-2019-1364An elevation of privilege vulnerability exists in Windows wh…7.8
- CVE-2019-13640In qBittorrent before 4.1.7, the function Application::runEx…
- CVE-2019-13643Stored XSS in EspoCRM before 5.6.4 allows remote attackers t…
- CVE-2019-13644Firefly III before 4.7.17.1 is vulnerable to stored XSS due …5.4
- CVE-2019-13645Firefly III before 4.7.17.3 is vulnerable to stored XSS due …
- CVE-2019-13646Firefly III before 4.7.17.3 is vulnerable to reflected XSS d…
Are you affected by CVE-2019-13638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
