CVE-2016-7543
published 2017-01-19CVE-2016-7543: Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
PriorityP344high8.4CVSS 3.0
AVLACLPRNUINSUCHIHAH
EPSS
0.58%
44.0th percentile
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bash | < bash 4.4-1 (bookworm) | bash 4.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | bash | <= 4.3 | — |
| gnu | bash | >= 0 < 4.4-1 | 4.4-1 |
| gnu | bash | >= 0 < 4.4-1 | 4.4-1 |
| gnu | bash | >= 0 < 4.4-1 | 4.4-1 |
| gnu | bash | >= 0 < 4.4-1 | 4.4-1 |
| gnu | bash | >= 0 < 4.3-7ubuntu1.7 | 4.3-7ubuntu1.7 |
| gnu | bash | >= 0 < 4.3-14ubuntu1.2 | 4.3-14ubuntu1.2 |
CVSS provenance
nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
vendor_ubuntu8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU Bash up to 4.3 SHELLOPTS/PS4 input validation (RHSA-2017:1931 / Nessus ID 96233)
vuldb·2026-05-14·CVSS 8.4
CVE-2016-7543 [HIGH] GNU Bash up to 4.3 SHELLOPTS/PS4 input validation (RHSA-2017:1931 / Nessus ID 96233)
A vulnerability was found in GNU Bash up to 4.3 and classified as critical. This vulnerability affects unknown code. The manipulation of the argument SHELLOPTS/PS4 as part of Environment Variable results in improper input validation.
This vulnerability is identified as CVE-2016-7543. The attack is only possible with local access. There is not any exploit available. This vulnerability has a historic impact due to its background and reception.
It is suggested to upgrade the affected component.
GHSA
GHSA-6xh6-xvh9-w4h5: Bash before 4
ghsa_unreviewed·2022-05-14
CVE-2016-7543 [HIGH] CWE-20 GHSA-6xh6-xvh9-w4h5: Bash before 4
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
OSV
bash vulnerabilities
osv·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] bash vulnerabilities
bash vulnerabilities
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
(CVE-2016-9401)
It was discovered that Bash incorrectly han
OSV
CVE-2016-7543: Bash before 4
osv·2017-01-19·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543: Bash before 4
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Ubuntu
Bash vulnerability
vendor_ubuntu·2017-08-01·CVSS 8.4
CVE-2016-7543 [HIGH] Bash vulnerability
Title: Bash vulnerability
Summary: A security issues were fixed in Bash.
USN-3294-1 fixed a vulnerability in Bash. This update provides the
corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. (CVE-2016-7543)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bash vulnerabilities
vendor_ubuntu·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] Bash vulnerabilities
Title: Bash vulnerabilities
Summary: Several security issues were fixed in Bash.
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
Red Hat
bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
vendor_redhat·2016-09-16·CVSS 8.4
CVE-2016-7543 [HIGH] CWE-77 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
An arbitrary command injection flaw was found in the way bash processed the SHELLOPTS and PS4 environment variables. A local, authenticated attacker could use this flaw to exploit poorly written setuid programs to elevate their privileges under certain circumstances.
Package: bash (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-7543: bash - Bash before 4.4 allows local users to execute arbitrary commands with root privi...
vendor_debian·2016·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543: bash - Bash before 4.4 allows local users to execute arbitrary commands with root privi...
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Scope: local
bookworm: resolved (fixed in 4.4-1)
bullseye: resolved (fixed in 4.4-1)
forky: resolved (fixed in 4.4-1)
sid: resolved (fixed in 4.4-1)
trixie: resolved (fixed in 4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
bugzilla·2016-09-27·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
Shells running as root inherited PS4 from the environment, allowing PS4 expansion performing command substitution. Local attacker could gain arbitrary code execution via bogus setuid binaries using system()/popen() by specially crafting SHELLOPTS+PS4 environment variables.
Public announcement:
http://seclists.org/oss-sec/2016/q3/617
Discussion:
Created bash tracking bugs for this issue:
Affects: fedora-all [bug 1379634]
---
Upstream patch (for bash-4.3):
http://lists.gnu.org/archive/html/bug-bash/2016-10/msg00009.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0725 https://rhn.redhat.com/errata/RHSA-2017-0725.html
---
This issue
Bugzilla
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution [fedora-all]
bugzilla·2016-09-27·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution [fedora-all]
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
http://rhn.redhat.com/errata/RHSA-2017-0725.htmlhttp://www.openwall.com/lists/oss-security/2016/09/26/9http://www.securityfocus.com/bid/93183http://www.securitytracker.com/id/1037812https://access.redhat.com/errata/RHSA-2017:1931https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.htmlhttps://security.gentoo.org/glsa/201701-02http://rhn.redhat.com/errata/RHSA-2017-0725.htmlhttp://www.openwall.com/lists/oss-security/2016/09/26/9http://www.securityfocus.com/bid/93183http://www.securitytracker.com/id/1037812https://access.redhat.com/errata/RHSA-2017:1931https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.htmlhttps://security.gentoo.org/glsa/201701-02
2017-01-19
Published