CVE-2019-13636

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
17/07/2019
Last modified:
07/11/2023

Description

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:patch:*:*:*:*:*:*:*:* 2.7.6 (including)