Vulnerability Description
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Patch | <= 2.7.6 |
Related Weaknesses (CWE)
References
- https://savannah.gnu.org/bugs/index.php?56683ExploitVendor Advisory
- https://savannah.gnu.org/bugs/index.php?56683ExploitVendor Advisory
FAQ
What is CVE-2019-20633?
CVE-2019-20633 is a vulnerability with a CVSS score of 5.5 (MEDIUM). GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exi...
How severe is CVE-2019-20633?
CVE-2019-20633 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20633?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Patch.