Directory Traversal Vulnerability in GNU Patch by GNU
CVE-2015-1396
7.5HIGH
What is CVE-2015-1396?
A Directory Traversal vulnerability in GNU Patch before version 2.7.4 permits remote attackers to exploit symlink attacks in patch files, allowing circumvention of file restrictions and writing arbitrary files to the system. This issue stems from an incomplete resolution of a previously identified vulnerability, CVE-2015-1196.