CVE-2019-13636

MEDIUM

GNU patch <2.7.6 - Info Disclosure

Title source: llm

Description

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Scores

CVSS v3 5.9
EPSS 0.0441
EPSS Percentile 88.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-59
Status published

Affected Products (1)

gnu/patch < 2.7.6

Timeline

Published Jul 17, 2019
Tracked Since Feb 18, 2026