VYPR
Unrated severityNVD Advisory· Published Mar 11, 2011· Updated Apr 29, 2026

CVE-2010-4651

CVE-2010-4651

Description

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

Affected products

5
  • GNU/Patch5 versions
    cpe:2.3:a:gnu:gnu_patch:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:gnu:gnu_patch:*:*:*:*:*:*:*:*range: <=2.6.1
    • cpe:2.3:a:gnu:gnu_patch:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:gnu_patch:2.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:gnu_patch:2.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:gnu_patch:2.6:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.