VYPR

by GNU

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-1395Hig0.497.50.04Aug 25, 2017Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
CVE-2014-9637Med0.365.50.00Aug 25, 2017GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
CVE-2015-11960.000.01Jan 21, 2015GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.