#patch clear

CVE-2019-13636: GNU patch v2.7.6 symlink-following in create_file() allows writing to arbitrary files

CVE-2018-6952: GNU patch double-free in another_hunk via ptrn_missing+repl_missing

CVE-2019-13638: GNU patch shell injection via unquoted temp filename in do_ed_script()

CVE-2019-13638: GNU patch shell injection via popen() in do_ed_script

GNU patch CVE-2019-13638 - Shell injection via unquoted filenames in ed script