Double Free Vulnerability in GNU Patch by GNU
CVE-2019-20633
5.5MEDIUM
What is CVE-2019-20633?
A double free vulnerability exists in the GNU Patch utility, specifically within the 'another_hunk' function in the pch.c file. This flaw can be exploited through a specially crafted patch file, potentially leading to a denial of service. The issue arises due to an incomplete fix for a prior vulnerability, allowing attackers to exploit the system. Users of GNU Patch versions up to 2.7.6 should be aware of this risk and take appropriate measures to safeguard their environments.