Logo
vulnerabilityCVE-2019-13636
Name
CVE-2019-13636
Source
NVD ( link)Debian ( link)
Description
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
patch
Patched

Vulnerability Ratings#


5.9
other
5.8
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.7.6
Patched
openwrt
master
2.8-r1
Not Affected
openwrt
openwrt-25.12
2.8-r1
Not Affected
yocto
kirkstone
2.7.6
Patched
yocto
master
2.8
Not Affected
yocto
scarthgap
2.7.6
Patched

Resolved with patches#


patch (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Don't follow symlinks unless --follow-symlinks is given
Andreas Gruenbacher <agruen@gnu.org>
CVE-2019-13636

patch (buildroot:master)

#
Title
Author
Resolve
1
Don't follow symlinks unless --follow-symlinks is given
Andreas Gruenbacher <agruen@gnu.org>
CVE-2019-13636

patch (yocto:kirkstone)

#
Title
Author
Resolve
1
Don't follow symlinks unless --follow-symlinks is given
Andreas Gruenbacher <agruen@gnu.org>
CVE-2019-13636

patch (yocto:scarthgap)

#
Title
Author
Resolve
1
Don't follow symlinks unless --follow-symlinks is given
Andreas Gruenbacher <agruen@gnu.org>
CVE-2019-13636