CVE Vulnerabilities

CVE-2015-1416

Published: Feb 05, 2018 | Modified: Mar 13, 2018
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Larry Walls patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 10.0 (including) 10.0 (including)
Freebsd Freebsd 10.1 (including) 10.1 (including)
Freebsd Freebsd 10.2 (including) 10.2 (including)
Patch Ubuntu upstream *

References