CVE-2015-1395

high
Published 2017-08-25 · Modified 2026-05-13
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
7.8
VIR risk
7.5

Description

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-1395

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://savannah.gnu.org/bugs/?44059

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://git.savannah.gnu.org/cgit/patch.git/commit/?id=17953b5893f7c9835f0dd2a704ba04e0371d2cbd

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://bugzilla.redhat.com/show_bug.cgi?id=1184490

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775873

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.ubuntu.com/usn/USN-2651-1

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.openwall.com/lists/oss-security/2015/01/27/28

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148953.html

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154214.html

OS impact

OSVersionStatusFixed in
fedora fedora20affected
fedora fedora21affected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu14.10affected
debian debianbookwormfixed2.7.3-1
debian debianbullseyefixed2.7.3-1
debian debianforkyfixed2.7.3-1
debian debiansidfixed2.7.3-1
debian debiantrixiefixed2.7.3-1

Application impact

VendorProductVersionsFixed
gnupatch{"endIncluding":"2.7.2"}

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.