Logo
vulnerabilityCVE-2019-13638
Name
CVE-2019-13638
Source
NVD ( link)Debian ( link)
Description
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
patch
Patched

Vulnerability Ratings#


7.8
other
9.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.7.6
Patched
buildroot
master
2.7.6
Patched
openwrt
master
2.8-r1
Not Affected
openwrt
openwrt-25.12
2.8-r1
Not Affected
yocto
kirkstone
2.7.6
Patched
yocto
master
2.8
Not Affected

Resolved with patches#


patch (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Invoke ed directly instead of using the shell
Andreas Gruenbacher <agruen@gnu.org>
CVE-2018-20969
CVE-2019-13638

patch (buildroot:master)

#
Title
Author
Resolve
1
Invoke ed directly instead of using the shell
Andreas Gruenbacher <agruen@gnu.org>
CVE-2018-20969
CVE-2019-13638

patch (yocto:kirkstone)

#
Title
Author
Resolve
1
Invoke ed directly instead of using the shell
Andreas Gruenbacher <agruen@gnu.org>
CVE-2018-20969
CVE-2019-13638

patch (yocto:scarthgap)

#
Title
Author
Resolve
1
Invoke ed directly instead of using the shell
Andreas Gruenbacher <agruen@gnu.org>
CVE-2018-20969
CVE-2019-13638