PT-2017-10117 · Gnu+5 · Bash+5

Fernando Muñoz

·

Published

2017-01-06

·

Updated

2025-08-06

·

CVE-2016-9401

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions bash (affected versions not specified)
Description The issue allows local users to bypass the restricted shell and cause a use-after-free via a crafted address, potentially related to the popd command in bash. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2880
CESA-2017_0725
CESA-2017_1931
CVE-2016-9401
DLA-1726-1
MGASA-2017-0005
OPENSUSE-SU-2024:10106-1
RHSA-2017:0725
RHSA-2017:1931
RHSA-2017_0725
RHSA-2017_1931
SUSE-SU-2017:1317-1
SUSE-SU-2017:1337-1
SUSE-SU-2017_1317-1
SUSE-SU-2017_1337-1
USN-3294-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Bash