PT-2012-1116 · Gnu+1 · Bash+1

Marcus Meissner

·

Publicado

2012-08-13

·

Atualizado

2017-08-29

·

CVE-2012-3410

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU Bash versions prior to 4.2 patch 33 GNU Bash versions prior to 4.2 p37
Description The issue is related to a stack-based buffer overflow in lib/sh/eaccess.c, which might allow local users to bypass intended restricted shell access. This can be achieved by using a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix. Multiple vulnerabilities in the bash package, specifically in versions before 4.2 p37, can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations For GNU Bash versions prior to 4.2 patch 33, update to version 4.2 patch 33 or later. For GNU Bash versions prior to 4.2 p37, update to version 4.2 p37 or later. As a temporary workaround, consider restricting access to the /dev/fd directory to minimize the risk of exploitation.

Exploit

Correção

Link Following

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09645
CVE-2012-3410
SUSE-SU-2012_0988-1
SUSE-SU-2014_1214-1

Produtos afetados

Bash
Suse