Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bash | Aug 30, 2017 | Aug 27, 2012 |
| Debian | — | Upgrade bash | Jul 30, 2024 | Aug 27, 2012 |
| Gentoo Linux | — | Upgrade app-shells/bash. | Oct 30, 2017 | Aug 27, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.1.0.0.24.2 on Solaris 11.1 | May 29, 2017 | Aug 27, 2012 |
| Suse | — | Upgrade readline-develUpgrade bashUpgrade bash-develUpgrade bash-loadables-debuginfoUpgrade bash-debuginfo-32bitUpgrade readline-devel-64bitUpgrade readline-x86Upgrade bash-x86Upgrade readlineUpgrade readline-docUpgrade libreadline6Upgrade libreadline6-debuginfo-32bitUpgrade readline-devel-32bitUpgrade bash-docUpgrade readline-64bitUpgrade libreadline6-x86Upgrade libreadline6-32bitUpgrade bash-debuginfo-x86Upgrade bash-loadablesUpgrade bash-debuginfoUpgrade bash-debugsourceUpgrade libreadline6-debuginfo-x86Upgrade libreadline6-debuginfoUpgrade readline-32bitUpgrade bash-lang | Dec 12, 2013 | Aug 27, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub