CVE-2016-9401
published 2017-01-23CVE-2016-9401: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.43%
34.5th percentile
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bash | < bash 4.4-3 (bookworm) | bash 4.4-3 (bookworm) |
| debian | debian_linux | — | — |
| gnu | bash | < 4.4 | 4.4 |
| gnu | bash | — | — |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.3-7ubuntu1.7 | 4.3-7ubuntu1.7 |
| gnu | bash | >= 0 < 4.3-14ubuntu1.2 | 4.3-14ubuntu1.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bash vulnerabilities
vendor_ubuntu·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] Bash vulnerabilities
Title: Bash vulnerabilities
Summary: Several security issues were fixed in Bash.
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
Red Hat
bash: popd controlled free
vendor_redhat·2016-11-17·CVSS 5.5
CVE-2016-9401 [MEDIUM] CWE-416 bash: popd controlled free
bash: popd controlled free
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
A denial of service flaw was found in the way bash handled popd commands. A poorly written shell script could cause bash to crash resulting in a local denial of service limited to a specific bash session.
Package: bash (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-9401: bash - popd in bash might allow local users to bypass the restricted shell and cause a ...
vendor_debian·2016·CVSS 5.5
CVE-2016-9401 [MEDIUM] CVE-2016-9401: bash - popd in bash might allow local users to bypass the restricted shell and cause a ...
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
Scope: local
bookworm: resolved (fixed in 4.4-3)
bullseye: resolved (fixed in 4.4-3)
forky: resolved (fixed in 4.4-3)
sid: resolved (fixed in 4.4-3)
trixie: resolved (fixed in 4.4-3)
GHSA
GHSA-888p-vvcc-q364: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address
ghsa_unreviewed·2022-05-13
CVE-2016-9401 [MEDIUM] CWE-416 GHSA-888p-vvcc-q364: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
OSV
bash vulnerabilities
osv·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] bash vulnerabilities
bash vulnerabilities
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
(CVE-2016-9401)
It was discovered that Bash incorrectly han
OSV
CVE-2016-9401: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address
osv·2017-01-23·CVSS 5.5
CVE-2016-9401 [MEDIUM] CVE-2016-9401: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9401 bash: popd controlled free
bugzilla·2016-11-18·CVSS 5.5
CVE-2016-9401 [MEDIUM] CVE-2016-9401 bash: popd controlled free
CVE-2016-9401 bash: popd controlled free
A vulnerability was found in popd. It can be tricked to free a user supplied address in the following way:
$ popd +-111111
This could be used to bypass restricted shells (rsh) on some environments to cause use-after-free.
References:
http://seclists.org/oss-sec/2016/q4/445
Discussion:
Created bash tracking bugs for this issue:
Affects: fedora-all [bug 1396387]
---
Upstream report:
https://lists.gnu.org/archive/html/bug-bash/2016-11/msg00099.html
Upstream patch:
https://lists.gnu.org/archive/html/bug-bash/2016-11/msg00116.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0725 https://rhn.redhat.com/errata/RHSA-2017-0725.html
---
This issue has been addressed in the following
Bugzilla
CVE-2016-9401 bash: popd controlled use-after-free [fedora-all]
bugzilla·2016-11-18·CVSS 5.5
CVE-2016-9401 [MEDIUM] CVE-2016-9401 bash: popd controlled use-after-free [fedora-all]
CVE-2016-9401 bash: popd controlled use-after-free [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
http://rhn.redhat.com/errata/RHSA-2017-0725.htmlhttp://www.openwall.com/lists/oss-security/2016/11/17/5http://www.openwall.com/lists/oss-security/2016/11/17/9http://www.securityfocus.com/bid/94398https://access.redhat.com/errata/RHSA-2017:1931https://lists.debian.org/debian-lts-announce/2019/03/msg00028.htmlhttps://security.gentoo.org/glsa/201701-02http://rhn.redhat.com/errata/RHSA-2017-0725.htmlhttp://www.openwall.com/lists/oss-security/2016/11/17/5http://www.openwall.com/lists/oss-security/2016/11/17/9http://www.securityfocus.com/bid/94398https://access.redhat.com/errata/RHSA-2017:1931https://lists.debian.org/debian-lts-announce/2019/03/msg00028.htmlhttps://security.gentoo.org/glsa/201701-02
2017-01-23
Published