Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35106.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-35106
Upstream
Published
2019-07-26T13:15:12Z
Modified
2026-04-01T05:11:55.904561Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2019-13638 affecting package patch for versions less than 2.7.6-9
Details

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.

References

Affected packages

Azure Linux:3 / patch

Package

Name
patch
Purl
pkg:rpm/azure-linux/patch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-9

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35106.json"