A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bash | Jul 30, 2024 | Jun 18, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 7, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bash | Jun 17, 2020 | Jun 18, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bash | Apr 30, 2021 | Jun 18, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bash | Sep 12, 2019 | Jun 18, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2019 |
| Suse | — | Upgrade libreadline6-32bitUpgrade bash-docUpgrade libreadline6Upgrade bashUpgrade readline-doc | Aug 9, 2024 | Jun 18, 2019 |
| Ubuntu | — | Upgrade bash | Nov 12, 2019 | Jun 18, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub