popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bash | Aug 30, 2017 | Jan 23, 2017 |
| Amazon_linux | — | Upgrade bash | Sep 1, 2017 | Jan 23, 2017 |
| Centos_linux | — | Upgrade bash-debuginfoUpgrade bash-docUpgrade bash | Aug 28, 2019 | Jan 23, 2017 |
| Debian | — | Upgrade bash | Mar 26, 2019 | Jan 23, 2017 |
| Gentoo Linux | — | Upgrade app-shells/bash. | Oct 30, 2017 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bash | Nov 30, 2017 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bash | Nov 30, 2017 | Jan 23, 2017 |
| Oracle Solaris | — | Upgrade shell/bash to version 4.4.11-0.175.3.17.0.4.0 on Solaris 11.3 | May 29, 2017 | Jan 23, 2017 |
| Oracle_linux | — | Upgrade bash-docUpgrade bash | Mar 28, 2017 | Nov 17, 2016 |
| Redhat_linux | — | Upgrade bashUpgrade bash-docNo solution existsUpgrade bash-debuginfo | Mar 21, 2017 | Jan 23, 2017 |
| Suse | — | Upgrade libreadline5Upgrade readline-develUpgrade libreadline7Upgrade libreadline5-32bitUpgrade libreadline6Upgrade readline-devel-32bitUpgrade libreadline5-x86Upgrade readline-docUpgrade bash-docUpgrade bash-langUpgrade bashUpgrade libreadline6-32bitUpgrade sles12sp2-docker-imageUpgrade libreadline7-32bitUpgrade bash-develUpgrade bash-x86 | May 2, 2017 | Jan 23, 2017 |
| Ubuntu | — | Upgrade bash | May 18, 2017 | Jan 23, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub