An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuitdifftype function in pch.c, aka a "mangled rename" issue.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2.7.1-4ubuntu2.4", "binary_name": "patch" }, { "binary_version": "2.7.1-4ubuntu2.4", "binary_name": "patch-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2.7.5-1ubuntu0.16.04.1", "binary_name": "patch" }, { "binary_version": "2.7.5-1ubuntu0.16.04.1", "binary_name": "patch-dbgsym" } ] }