CVE-2017-5932

Severity
7.8HIGH
EPSS
0.2%
top 54.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateMay 17

Description

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianbash< 4.4-3+3
NVDgnu/bash4.4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7893-9j9h-935c: The path autocompletion feature in Bash 42022-05-17
CVEList
CVE-2017-5932: The path autocompletion feature in Bash 42017-03-27
OSV
CVE-2017-5932: The path autocompletion feature in Bash 42017-03-27

📋Vendor Advisories

3
Ubuntu
Bash vulnerabilities2017-05-17
Red Hat
bash: Code execution in bash autocompletion2017-01-20
Debian
CVE-2017-5932: bash - The path autocompletion feature in Bash 4.4 allows local users to gain privilege...2017

💬Community

1
Bugzilla
CVE-2017-5932 bash: Code execution in bash autocompletion2017-02-09