CVE-2010-4651

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
gnugnu_patch
𝑥
≤ 2.6.1
gnugnu_patch
2.5
gnugnu_patch
2.5.4
gnugnu_patch
2.5.9
gnugnu_patch
2.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
patch
sid
unimportant
trixie
unimportant
bookworm
unimportant
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
patch
vivid
not-affected
utopic
not-affected
trusty
not-affected
precise
Fixed 2.6.1-3ubuntu0.1
released
References