ALPINE-CVE-2019-13636

Source
https://security.alpinelinux.org/vuln/CVE-2019-13636
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2019-13636.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2019-13636
Upstream
Published
2019-07-17T21:15:11Z
Modified
2025-09-30T05:14:21.110550Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

References

Affected packages

Alpine:v3.10

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.11

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.12

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.13

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.14

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.15

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.16

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.17

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.18

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.19

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.20

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.21

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.22

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4

Alpine:v3.7

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.5-r3

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.5-r2

Alpine:v3.8

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r3

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2

Alpine:v3.9

patch

Package

Name
patch
Purl
pkg:apk/alpine/patch?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-r5

Affected versions

2.*

2.5.9-r0
2.6-r0
2.6.1-r0
2.6.1-r1
2.6.1-r2
2.6.1-r3
2.7-r0
2.7.1-r0
2.7.1-r1
2.7.3-r0
2.7.4-r0
2.7.5-r0
2.7.5-r1
2.7.6-r0
2.7.6-r1
2.7.6-r2
2.7.6-r3
2.7.6-r4