cbcvebase.
CVE-2016-7543
published 2017-01-19

CVE-2016-7543: Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

high8.4CVSS 3.0
AVLACLPRNUINSUCHIHAH
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianbash< bash 4.4-1 (bookworm)bash 4.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gnubash<= 4.3
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.3-7ubuntu1.74.3-7ubuntu1.7
gnubash>= 0 < 4.3-14ubuntu1.24.3-14ubuntu1.2

CVSS provenance

nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.4HIGH