PT-2017-9218 · Gnu+5 · Bash+5

Publicado

2016-11-21

·

Atualizado

2018-12-19

·

CVE-2016-7543

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bash versions prior to 4.4
Description The issue allows local users to execute arbitrary commands with root privileges by manipulating the SHELLOPTS and PS4 environment variables.
Recommendations For versions prior to 4.4, update to version 4.4 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2502
ALT-PU-2018-2880
CESA-2017_0725
CESA-2017_1931
CVE-2016-7543
DLA-680-1
MGASA-2016-0393
OPENSUSE-SU-2018_1419-1
RHSA-2017:0725
RHSA-2017:1931
RHSA-2017_0725
RHSA-2017_1931
SUSE-SU-2016:2872-1
SUSE-SU-2017:0302-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2018:1398-1
SUSE-SU-2018:1398-2
USN-3294-1
USN-3294-2

Produtos afetados

Alt Linux
Bash
Centos
Red Hat
Suse
Ubuntu