CVE-2015-1196

GNU patch <2.7.1 - RCE

Title source: llm

Description

GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.

Scores

EPSS 0.0085
EPSS Percentile 74.6%

Classification

CWE
CWE-59
Status draft

Affected Products (4)

opensuse/opensuse
opensuse/opensuse
oracle/solaris
gnu/patch

Timeline

Published Jan 21, 2015
Tracked Since Feb 18, 2026