An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuitdifftype function in pch.c, aka a "mangled rename" issue.
{ "binaries": [ { "binary_name": "patch", "binary_version": "2.7.1-4ubuntu2.4" }, { "binary_name": "patch-dbgsym", "binary_version": "2.7.1-4ubuntu2.4" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "patch", "binary_version": "2.7.5-1ubuntu0.16.04.1" }, { "binary_name": "patch-dbgsym", "binary_version": "2.7.5-1ubuntu0.16.04.1" } ], "availability": "No subscription required" }