{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2019/cve-2019-20633-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-11T18:08:10Z",
      "generator": {
        "date": "2026-09-11T18:08:10Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2019-20633-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2019-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2019-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-11T18:08:10Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2019-20633"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7.armel",
                "product": {
                  "name": "patch-0:2.7.6-7.armel",
                  "product_id": "patch-0:2.7.6-7.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/patch@2.7.6-7?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7.arm64",
                "product": {
                  "name": "patch-0:2.7.6-7.arm64",
                  "product_id": "patch-0:2.7.6-7.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/patch@2.7.6-7?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7.amd64",
                "product": {
                  "name": "patch-0:2.7.6-7.amd64",
                  "product_id": "patch-0:2.7.6-7.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/patch@2.7.6-7?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7+tuxcare.els1.armel",
                "product": {
                  "name": "patch-0:2.7.6-7+tuxcare.els1.armel",
                  "product_id": "patch-0:2.7.6-7+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/patch@2.7.6-7%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7+tuxcare.els1.arm64",
                "product": {
                  "name": "patch-0:2.7.6-7+tuxcare.els1.arm64",
                  "product_id": "patch-0:2.7.6-7+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/patch@2.7.6-7%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "patch-0:2.7.6-7+tuxcare.els1.amd64",
                "product": {
                  "name": "patch-0:2.7.6-7+tuxcare.els1.amd64",
                  "product_id": "patch-0:2.7.6-7+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/patch@2.7.6-7%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7+tuxcare.els1.armel"
        },
        "product_reference": "patch-0:2.7.6-7+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7.armel as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7.armel"
        },
        "product_reference": "patch-0:2.7.6-7.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7+tuxcare.els1.arm64"
        },
        "product_reference": "patch-0:2.7.6-7+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7.arm64 as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7.arm64"
        },
        "product_reference": "patch-0:2.7.6-7.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7+tuxcare.els1.amd64"
        },
        "product_reference": "patch-0:2.7.6-7+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "patch-0:2.7.6-7.amd64 as a component of Debian 11",
          "product_id": "Debian-11:patch-0:2.7.6-7.amd64"
        },
        "product_reference": "patch-0:2.7.6-7.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2019-20633",
      "cwe": {
        "id": "CWE-415",
        "name": "Double Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:patch-0:2.7.6-7+tuxcare.els1.amd64",
          "Debian-11:patch-0:2.7.6-7+tuxcare.els1.arm64",
          "Debian-11:patch-0:2.7.6-7+tuxcare.els1.armel",
          "Debian-11:patch-0:2.7.6-7.amd64",
          "Debian-11:patch-0:2.7.6-7.arm64",
          "Debian-11:patch-0:2.7.6-7.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2019-20633"
        },
        {
          "category": "external",
          "summary": "https://savannah.gnu.org/bugs/index.php?56683",
          "url": "https://savannah.gnu.org/bugs/index.php?56683"
        }
      ],
      "release_date": "2020-03-25T17:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-07T14:39:42.414141Z",
          "details": "This flaw is a local, user‑interaction‑required double‑free in GNU patch that only crashes the patch process when a crafted patch file is applied, with no confidentiality or integrity impact. The patch utility is a non‑network‑facing, on‑demand command‑line tool, so exploitation requires someone to intentionally run it against attacker‑supplied input rather than it being reachable through services or automation. Given the DoS‑only outcome and the need for deliberate local execution of an untrusted patch file, this is appropriately low‑priority for managed server/VM environments.",
          "product_ids": [
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.amd64",
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.arm64",
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.armel",
            "Debian-11:patch-0:2.7.6-7.amd64",
            "Debian-11:patch-0:2.7.6-7.arm64",
            "Debian-11:patch-0:2.7.6-7.armel"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.amd64",
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.arm64",
            "Debian-11:patch-0:2.7.6-7+tuxcare.els1.armel",
            "Debian-11:patch-0:2.7.6-7.amd64",
            "Debian-11:patch-0:2.7.6-7.arm64",
            "Debian-11:patch-0:2.7.6-7.armel"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}