← Vulnerability feed

Vulnerability record · CVE-2019-13636 · published 17 July 2019

CVE-2019-13636: Gnu patch link following vulnerability

Gnu · Patch

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

5.9 CVSS 3.0 Medium EPSS 3.9% · top 10.1% CWE-59 · Link following
5.9CVSS 3.0 base score, v2 5.8
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71a Mailing ListPatchVendor Advisory
https://github.com/irsl/gnu-patch-vulnerabilities
https://lists.debian.org/debian-lts-announce/2019/07/msg00016.html Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UB
https://seclists.org/bugtraq/2019/Aug/29
https://seclists.org/bugtraq/2019/Jul/54
https://security.gentoo.org/glsa/201908-22
https://security.netapp.com/advisory/ntap-20190828-0001/
https://usn.ubuntu.com/4071-1/
https://usn.ubuntu.com/4071-2/
https://www.debian.org/security/2019/dsa-4489
http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71a Mailing ListPatchVendor Advisory
https://github.com/irsl/gnu-patch-vulnerabilities
https://lists.debian.org/debian-lts-announce/2019/07/msg00016.html Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UB
https://seclists.org/bugtraq/2019/Aug/29
https://seclists.org/bugtraq/2019/Jul/54
https://security.gentoo.org/glsa/201908-22
https://security.netapp.com/advisory/ntap-20190828-0001/
https://usn.ubuntu.com/4071-1/
https://usn.ubuntu.com/4071-2/
https://www.debian.org/security/2019/dsa-4489

Track CVE-2019-13636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-20969Gnu patch os command injection vulnerabilitydo_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…EPSS 2.7%7.8CVE-2019-13638Gnu patch os command injection vulnerabilityGNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…EPSS 4.5%7.8CVE-2018-1000156Gnu patch improper input validation vulnerabilityGNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…EPSS 5.3%7.5CVE-2015-1396Gnu patch path traversal vulnerabilityA Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…EPSS 3.3%7.5CVE-2018-6951Gnu patch null pointer dereference vulnerabilityAn issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…EPSS 8.4%7.5CVE-2018-6952Gnu patch double free vulnerabilityA double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.EPSS 8.2%7.5CVE-2015-1395Fedoraproject fedora path traversal vulnerabilityDirectory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f…EPSS 11%5.5CVE-2021-45261Gnu patch vulnerabilityAn Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2019-13636), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.