CVE-2017-5932
published 2017-03-27CVE-2017-5932: The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.5th percentile
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bash | < bash 4.4-3 (bookworm) | bash 4.4-3 (bookworm) |
| gnu | bash | — | — |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.4-3 | 4.4-3 |
| gnu | bash | >= 0 < 4.3-7ubuntu1.7 | 4.3-7ubuntu1.7 |
| gnu | bash | >= 0 < 4.3-14ubuntu1.2 | 4.3-14ubuntu1.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bash vulnerabilities
vendor_ubuntu·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] Bash vulnerabilities
Title: Bash vulnerabilities
Summary: Several security issues were fixed in Bash.
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
Red Hat
bash: Code execution in bash autocompletion
vendor_redhat·2017-01-20·CVSS 7.8
CVE-2017-5932 [HIGH] CWE-20 bash: Code execution in bash autocompletion
bash: Code execution in bash autocompletion
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Statement: This issue did not affect the versions of bash as shipped with Red Hat Enterprise Linux as they did not include the commit which introduced it.
Package: bash (Red Hat Enterprise Linux 5) - Not affected
Package: bash (Red Hat Enterprise Linux 6) - Not affected
Package: bash (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-5932: bash - The path autocompletion feature in Bash 4.4 allows local users to gain privilege...
vendor_debian·2017·CVSS 7.8
CVE-2017-5932 [HIGH] CVE-2017-5932: bash - The path autocompletion feature in Bash 4.4 allows local users to gain privilege...
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Scope: local
bookworm: resolved (fixed in 4.4-3)
bullseye: resolved (fixed in 4.4-3)
forky: resolved (fixed in 4.4-3)
sid: resolved (fixed in 4.4-3)
trixie: resolved (fixed in 4.4-3)
GHSA
GHSA-7893-9j9h-935c: The path autocompletion feature in Bash 4
ghsa_unreviewed·2022-05-17
CVE-2017-5932 [HIGH] CWE-20 GHSA-7893-9j9h-935c: The path autocompletion feature in Bash 4
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
OSV
bash vulnerabilities
osv·2017-05-17·CVSS 7.5
CVE-2016-0634 [HIGH] bash vulnerabilities
bash vulnerabilities
Bernd Dietzel discovered that Bash incorrectly expanded the hostname when
displaying the prompt. If a remote attacker were able to modify a hostname,
this flaw could be exploited to execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.
(CVE-2016-0634)
It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)
It was discovered that Bash incorrectly handled the popd command. A remote
attacker could possibly use this issue to bypass restricted shells.
(CVE-2016-9401)
It was discovered that Bash incorrectly han
OSV
CVE-2017-5932: The path autocompletion feature in Bash 4
osv·2017-03-27·CVSS 7.8
CVE-2017-5932 [HIGH] CVE-2017-5932: The path autocompletion feature in Bash 4
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/bash.git/commit/?id=4f747edc625815f449048579f6e65869914dd715http://www.openwall.com/lists/oss-security/2017/02/08/3http://www.securityfocus.com/bid/96136https://lists.gnu.org/archive/html/bug-bash/2017-01/msg00034.htmlhttp://git.savannah.gnu.org/cgit/bash.git/commit/?id=4f747edc625815f449048579f6e65869914dd715http://www.openwall.com/lists/oss-security/2017/02/08/3http://www.securityfocus.com/bid/96136https://lists.gnu.org/archive/html/bug-bash/2017-01/msg00034.html
2017-03-27
Published