A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-bash | Jul 30, 2024 | Jun 18, 2019 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Oct 7, 2019 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-bash | Jun 17, 2020 | Jun 18, 2019 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-bash | Apr 30, 2021 | Jun 18, 2019 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-bash | Sep 12, 2019 | Jun 18, 2019 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Jun 18, 2019 | |
| Suse | — | suse-upgrade-bashsuse-upgrade-bash-docsuse-upgrade-libreadline6suse-upgrade-libreadline6-32bitsuse-upgrade-readline-doc | Aug 9, 2024 | Jun 18, 2019 |
| Ubuntu | ubuntu-upgrade-bash | Nov 12, 2019 | Jun 18, 2019 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jun 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub