techtonik / python-patch

Library to parse and apply unified diffs
https://pypi.python.org/pypi/patch
106 stars 63 forks source link

GNU Patch still gets CVE #65

Open techtonik opened 4 years ago

techtonik commented 4 years ago

GNU Patch suffers from vulnerabilities even in 2019.

https://www.cvedetails.com/cve/CVE-2019-13638/ is especially evil.

Need to release and package new version of python-patch as a safe alternative.