LWN.net Logo

patch: arbitrary file creation

Package(s):patch CVE #(s):CVE-2010-4651
Created:February 14, 2011 Updated:September 14, 2012
Description: From the Pardus advisory:

It was discovered that the patch utility allowed '..' in path names which could allow an attacker to create arbitrary files using a specially-crafted patch file.

Alerts:
Fedora FEDORA-2011-1269 2011-02-10
Fedora FEDORA-2011-1272 2011-02-10
Pardus 2011-28 2011-02-12
Slackware SSA:2012-257-02 2012-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds