PT-2017-16767 · Gnu+1 · Bash+1

Jens Heyens

·

Published

2017-03-27

·

Updated

2017-05-17

·

CVE-2017-5932

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bash version 4.4
Description The issue allows local users to gain privileges through a crafted filename. This is achieved by starting the filename with a " (double quote) character and a command substitution metacharacter.
Recommendations For Bash version 4.4, consider disabling the path autocompletion feature as a temporary workaround until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5932
USN-3294-1

Affected Products

Bash
Ubuntu