CyberRota Analysis
AI-GeneratedGNU patch is susceptible to a NULL pointer dereference due to improper handling of consecutive end-of-file newline markers in specially crafted unified-diff patch files. This vulnerability can lead to application crashes, resulting in a denial of service when processing malicious patch files. Developers and system administrators using GNU patch should prioritize this issue to mitigate potential disruptions in service.
Original NVD Description
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
Related CVEs
Other vulnerabilities affecting the same vendor(s)