Vulnerability Name:

CVE-2014-9637 (CCN-100333)

Assigned:2015-01-23
Published:2015-01-23
Updated:2017-08-30
Summary:GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
1.9 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: CONFIRM
Type: Patch, Third Party Advisory
http://advisories.mageia.org/MGASA-2015-0068.html

Source: MITRE
Type: CNA
CVE-2014-9637

Source: CCN
Type: Gnu patch Git Repository
patch.git - GNU patch

Source: FEDORA
Type: Patch, Third Party Advisory
FEDORA-2015-1165

Source: FEDORA
Type: Patch, Third Party Advisory
FEDORA-2015-1134

Source: MLIST
Type: Mailing List, Patch, Third Party Advisory
[oss-security] 20150122 Re: CVE request: directory traversal flaw in patch

Source: BID
Type: Third Party Advisory, VDB Entry
72286

Source: CCN
Type: BID-72286
GNU patch 'set_hunkmax()' Function Denial of Service Vulnerability

Source: UBUNTU
Type: Patch, Third Party Advisory
USN-2651-1

Source: CCN
Type: Red Hat Bugzilla – Bug 1185262
(CVE-2014-9637) CVE-2014-9637 patch: local denial of service with a crafted patch

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1185262

Source: XF
Type: UNKNOWN
gnupatch-cve20149637-dos(100333)

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=0c08d7a902c6fdd49b704623a12d8d672ef18944

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://savannah.gnu.org/bugs/?44051

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-9637

Vulnerable Configuration:Configuration 1:
  • cpe:/o:fedoraproject:fedora:20:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:21:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:mageia:mageia:4.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:gnu:patch:*:*:*:*:*:*:*:* (Version <= 2.7.2)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20149637
    V
    CVE-2014-9637
    2022-05-20
    oval:org.opensuse.security:def:32241
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:34014
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:33063
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:34610
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:30272
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:30144
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:32202
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:34552
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:29425
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:33006
    P
    Security update for openssl (Low)
    2021-09-20
    oval:org.opensuse.security:def:30126
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:29408
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:30107
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:30215
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:33930
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:31199
    P
    Security update for freeradius-server (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:36293
    P
    socat-1.7.0.0-1.16.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36251
    P
    ntp-4.2.8p2-2.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:33919
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:33918
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:29369
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:32911
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:34659
    P
    Security update for python36 (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:31356
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:31355
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:29469
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:35235
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:35569
    P
    kde4-kgreeter-plugins-4.3.5-0.8.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35542
    P
    evolution-data-server-2.28.2-0.10.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35613
    P
    mono-core-2.0.1-1.19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32697
    P
    kvm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29114
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:34698
    P
    Security update for xorg-x11-libXv
    2020-12-01
    oval:org.opensuse.security:def:32686
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29030
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32685
    P
    java-1_4_2-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28973
    P
    Security update for rpcbind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28887
    P
    Security update for compat-openssl097g (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30718
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28756
    P
    Security update for libpng
    2020-12-01
    oval:org.opensuse.security:def:34394
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30674
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28687
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34305
    P
    Security update for quagga (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30655
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28676
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34248
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30616
    P
    Security update for tomcat6
    2020-12-01
    oval:org.opensuse.security:def:29212
    P
    Security update for patch (Important)
    2020-12-01
    oval:org.opensuse.security:def:28675
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:34150
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30567
    P
    Security update for libvirt
    2020-12-01
    oval:org.opensuse.security:def:29176
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:30512
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:30358
    P
    Security update for wget
    2020-12-01
    oval:org.opensuse.security:def:35503
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34196
    P
    Security update for patch (Important)
    2020-12-01
    oval:org.opensuse.security:def:35454
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34156
    P
    Security update for openssh
    2020-12-01
    oval:org.opensuse.security:def:35395
    P
    Security update for openslp (Important)
    2020-12-01
    oval:org.opensuse.security:def:31564
    P
    Security update for squid3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29994
    P
    Security update for libtcnative-1-0 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31520
    P
    Security update for rpcbind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29920
    P
    Security update for libevent (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35145
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31499
    P
    Security update for python-paramiko (Important)
    2020-12-01
    oval:org.opensuse.security:def:29909
    P
    Security update for libHX13
    2020-12-01
    oval:org.opensuse.security:def:35088
    P
    Security update for kdebase4-workspace
    2020-12-01
    oval:org.opensuse.security:def:31460
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29908
    P
    Security update for lha (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34987
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31411
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34851
    P
    Security update for bsdtar (Important)
    2020-12-01
    oval:org.opensuse.security:def:28538
    P
    Security update for coreutils
    2020-12-01
    oval:org.opensuse.security:def:34767
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:28494
    P
    Security update for openssl1
    2020-12-01
    oval:org.opensuse.security:def:34756
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31112
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28479
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35446
    P
    Security update for patch (Important)
    2020-12-01
    oval:org.opensuse.security:def:34755
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:31055
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28440
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:35405
    P
    Security update for openssh-openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30963
    P
    Security update for gpgme
    2020-12-01
    oval:org.opensuse.security:def:28391
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:33518
    P
    Security update for sendmail
    2020-12-01
    oval:org.opensuse.security:def:30831
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28338
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33474
    P
    Security update for libesmtp
    2020-12-01
    oval:org.opensuse.security:def:30757
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28186
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33451
    P
    Security update for GNOME screensaver
    2020-12-01
    oval:org.opensuse.security:def:30746
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28102
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:33412
    P
    Security update for Salt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31394
    P
    Security update for patch (Important)
    2020-12-01
    oval:org.opensuse.security:def:30745
    P
    Security update for ansible, python-straight-plugin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28045
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33363
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27961
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:33306
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27833
    P
    Security update for mercurial
    2020-12-01
    oval:org.opensuse.security:def:33150
    P
    libgcc_s1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27769
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27758
    P
    Security update for gnutls
    2020-12-01
    oval:org.opensuse.security:def:27757
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:29320
    P
    Security update for IBM Java 1.4.2
    2020-12-01
    oval:org.opensuse.security:def:32776
    P
    python on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29266
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:34723
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:com.ubuntu.trusty:def:20149637000
    V
    CVE-2014-9637 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-08-25
    oval:com.ubuntu.precise:def:20149637000
    V
    CVE-2014-9637 on Ubuntu 12.04 LTS (precise) - medium.
    2014-12-31
    BACK
    fedoraproject fedora 20
    fedoraproject fedora 21
    mageia mageia 4.0
    canonical ubuntu linux 12.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 14.10
    gnu patch *