CVE-2012-3410
published 2012-08-27CVE-2012-3410: Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long…
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.4th percentile
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bash | < bash 4.2-4 (bookworm) | bash 4.2-4 (bookworm) |
| gnu | bash | — | — |
| gnu | bash | >= 0 < 4.2-4 | 4.2-4 |
| gnu | bash | >= 0 < 4.2-4 | 4.2-4 |
| gnu | bash | >= 0 < 4.2-4 | 4.2-4 |
| gnu | bash | >= 0 < 4.2-4 | 4.2-4 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g5r-93v7-fh2w: Stack-based buffer overflow in lib/sh/eaccess
ghsa_unreviewed·2022-05-17
CVE-2012-3410 [MEDIUM] CWE-119 GHSA-8g5r-93v7-fh2w: Stack-based buffer overflow in lib/sh/eaccess
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
OSV
CVE-2012-3410: Stack-based buffer overflow in lib/sh/eaccess
osv·2012-08-27·CVSS 4.6
CVE-2012-3410 [MEDIUM] CVE-2012-3410: Stack-based buffer overflow in lib/sh/eaccess
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
Red Hat
bash: Stack-based buffer overflow (crash) when expanding /dev/fd file names
vendor_redhat·2012-07-10·CVSS 4.6
CVE-2012-3410 [MEDIUM] CWE-121 bash: Stack-based buffer overflow (crash) when expanding /dev/fd file names
bash: Stack-based buffer overflow (crash) when expanding /dev/fd file names
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
Statement: Red Hat does not consider this do be a security issue. The affected code is present in Red Hat Enterprise Linux 5 and 6, but due to use of FORTIFY_SOURCE protections the impact would be limited to a crash. Therefore, there are no plans to correct this issue in Red Hat Enterprise Linux 5 and 6.
Package: bash (Red Hat Enterprise Linux 5) - Not affected
Package: bash (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-3410: bash - Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 ...
vendor_debian·2012·CVSS 4.6
CVE-2012-3410 [MEDIUM] CVE-2012-3410: bash - Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 ...
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
Scope: local
bookworm: resolved (fixed in 4.2-4)
bullseye: resolved (fixed in 4.2-4)
forky: resolved (fixed in 4.2-4)
sid: resolved (fixed in 4.2-4)
trixie: resolved (fixed in 4.2-4)
No detection rules found.
No public exploits indexed.
ftp://ftp.gnu.org/pub/gnu/bash/bash-4.2-patches/bash42-033http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681278http://secunia.com/advisories/51086http://security.gentoo.org/glsa/glsa-201210-05.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:128http://www.openwall.com/lists/oss-security/2012/07/11/11http://www.openwall.com/lists/oss-security/2012/07/11/22http://www.openwall.com/lists/oss-security/2012/07/12/4http://www.securityfocus.com/bid/54937https://exchange.xforce.ibmcloud.com/vulnerabilities/77551https://hermes.opensuse.org/messages/15227834ftp://ftp.gnu.org/pub/gnu/bash/bash-4.2-patches/bash42-033http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681278http://secunia.com/advisories/51086http://security.gentoo.org/glsa/glsa-201210-05.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:128http://www.openwall.com/lists/oss-security/2012/07/11/11http://www.openwall.com/lists/oss-security/2012/07/11/22http://www.openwall.com/lists/oss-security/2012/07/12/4http://www.securityfocus.com/bid/54937https://exchange.xforce.ibmcloud.com/vulnerabilities/77551https://hermes.opensuse.org/messages/15227834
2012-08-27
Published