popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bash | Aug 30, 2017 | Jan 23, 2017 |
| Amazon_linux | — | Upgrade bash | Sep 1, 2017 | Jan 23, 2017 |
| Centos_linux | — | Upgrade bash-debuginfoUpgrade bash-docUpgrade bash | Aug 28, 2019 | Jan 23, 2017 |
| Debian | — | Upgrade bash | Mar 26, 2019 | Jan 23, 2017 |
| Gentoo Linux | — | Upgrade app-shells/bash. | Oct 30, 2017 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bash | Nov 30, 2017 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bash | Nov 30, 2017 | Jan 23, 2017 |
| Oracle Solaris | — | Upgrade shell/bash to version 4.4.11-0.175.3.17.0.4.0 on Solaris 11.3 | May 29, 2017 | Jan 23, 2017 |
| Oracle_linux | — | Upgrade bashUpgrade bash-doc | Mar 28, 2017 | Nov 17, 2016 |
| Redhat_linux | — | No solution existsUpgrade bash-debuginfoUpgrade bash-docUpgrade bash | Mar 21, 2017 | Jan 23, 2017 |
| Suse | — | Upgrade libreadline6Upgrade libreadline5-32bitUpgrade libreadline7Upgrade readline-develUpgrade libreadline5Upgrade readline-devel-32bitUpgrade libreadline5-x86Upgrade bash-langUpgrade readline-docUpgrade bash-x86Upgrade bash-develUpgrade bash-docUpgrade libreadline7-32bitUpgrade sles12sp2-docker-imageUpgrade bashUpgrade libreadline6-32bit | May 2, 2017 | Jan 23, 2017 |
| Ubuntu | — | Upgrade bash | May 18, 2017 | Jan 23, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub