PT-2017-9218 · Gnu+5 · Bash+5

Published

2016-11-21

·

Updated

2018-12-19

·

CVE-2016-7543

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bash versions prior to 4.4
Description The issue allows local users to execute arbitrary commands with root privileges by manipulating the SHELLOPTS and PS4 environment variables.
Recommendations For versions prior to 4.4, update to version 4.4 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2502
ALT-PU-2018-2880
CESA-2017_0725
CESA-2017_1931
CVE-2016-7543
DLA-680-1
MGASA-2016-0393
OPENSUSE-SU-2018_1419-1
RHSA-2017:0725
RHSA-2017:1931
RHSA-2017_0725
RHSA-2017_1931
SUSE-SU-2016:2872-1
SUSE-SU-2017:0302-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2018:1398-1
SUSE-SU-2018:1398-2
USN-3294-1
USN-3294-2

Affected Products

Alt Linux
Bash
Centos
Red Hat
Suse
Ubuntu