Description
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
In plain language
AI Worth attentionIf your system runs GNU Patch 2.7.6, a malicious patch file could make the patch tool run code—this is mainly a risk for people who apply untrusted patch files.
CVE-2018-1000156 is a local code execution issue in GNU Patch 2.7.6 where processing a crafted patch file can trigger unsafe invocation of the internal `ed` editor with unsanitized input.
What to do now
- Check which version of the
patchprogram you have installed (look for GNU Patch and whether it is 2.7.6). - If you are on GNU Patch 2.7.6, upgrade to a version newer than 2.7.6 from your distro’s updates.
- Stop applying patch files from email, the internet, or unknown sources; only apply patches from trusted repositories or vendors.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-1000156 and every CVE in our database. Create a free account — no credit card required.
Create Free Account