Security readout for executives and security teams
GNU patch through 2.7.6 mishandles symbolic links in some non-input-file cases. The business risk is highest where build, packaging, or automation systems apply patch files from outside trusted workflows, because file handling may not stay within the intended target path. Exposure is most likely on Unix/Linux systems with GNU patch through 2.7.6, especially developer workstations, CI, package builders, and appliances that process externally supplied patch files. Handle as a build-chain and developer-tooling exposure rather than an internet-facing emergency. Patch promptly on systems that process outside contributions or third-party patches, and document any vendor-dependent exceptions. Mitigation focus: Apply GNU patch security updates from your OS or appliance vendor.; Prioritize CI, build servers, packaging systems, and developer jump hosts.; Avoid applying untrusted patch files on privileged or shared systems..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-13636 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71aCVE reference · x_refsource_MISC
- [debian-lts-announce] 20190719 [SECURITY] [DLA 1856-1] patch security updateCVE reference · mailing-list, x_refsource_MLIST
- USN-4071-1CVE reference · vendor-advisory, x_refsource_UBUNTU
- USN-4071-2CVE reference · vendor-advisory, x_refsource_UBUNTU
- DSA-4489CVE reference · vendor-advisory, x_refsource_DEBIAN
- 20190730 [SECURITY] [DSA 4489-1] patch security updateCVE reference · mailing-list, x_refsource_BUGTRAQ
- 20190816 Details about recent GNU patch vulnerabilitiesCVE reference · mailing-list, x_refsource_BUGTRAQ
- GLSA-201908-22CVE reference · vendor-advisory, x_refsource_GENTOO
- FEDORA-2019-ac709da87fCVE reference · vendor-advisory, x_refsource_FEDORA
- https://security.netapp.com/advisory/ntap-20190828-0001/CVE reference · x_refsource_CONFIRM
- https://github.com/irsl/gnu-patch-vulnerabilitiesCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
