CVE-2019-14868
published 2020-04-02CVE-2019-14868: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.39%
69.4th percentile
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.15.5 | 10.15.5 |
| debian | debian_linux | — | — |
| debian | ksh | < ksh 2020.0.0-2.1 (bullseye) | ksh 2020.0.0-2.1 (bullseye) |
| kornshell | ksh | — | — |
| ksh_project | ksh | — | — |
| ksh_project | ksh | >= 0 < 2020.0.0-2.1 | 2020.0.0-2.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
vendor_redhat·2019-12-13·CVSS 7.4
CVE-2019-14868 [HIGH] CWE-77 ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
A flaw was found in the way ksh evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to expl
Debian
CVE-2019-14868: ksh - In ksh version 20120801, a flaw was found in the way it evaluates certain enviro...
vendor_debian·2019·CVSS 7.4
CVE-2019-14868 [HIGH] CVE-2019-14868: ksh - In ksh version 20120801, a flaw was found in the way it evaluates certain enviro...
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
Scope: local
bullseye: resolved (fixed in 2020.0.0-2.1)
GHSA
GHSA-2x84-7422-962r: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables
ghsa_unreviewed·2022-05-24
CVE-2019-14868 [HIGH] CWE-77 GHSA-2x84-7422-962r: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
OSV
CVE-2019-14868: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables
osv·2020-04-02·CVSS 7.8
CVE-2019-14868 [HIGH] CVE-2019-14868: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14868 ksh: environment variables on startup are interpreted as arithmetic expression leading to code injection [fedora-all]
bugzilla·2020-01-13·CVSS 7.4
CVE-2019-14868 [HIGH] CVE-2019-14868 ksh: environment variables on startup are interpreted as arithmetic expression leading to code injection [fedora-all]
CVE-2019-14868 ksh: environment variables on startup are interpreted as arithmetic expression leading to code injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2019-14868 ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
bugzilla·2019-10-01·CVSS 7.4
CVE-2019-14868 [HIGH] CVE-2019-14868 ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
CVE-2019-14868 ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
Korn Shell is interpreting the contents of some environment variables on startup as an arithmetic expression and therefore potentially causing code injection vulnerabilities.
Discussion:
(In reply to Marian Rehak from comment #1)
> Acknowledgments:
>
> Name: Stephane Chazelas
Actually, most of the issues were found by Oliver Kiddle (zsh developer).
---
During ksh startup, environment variables that are expected to contain a number are evaluated as an arithmetic expression. If an attacker is able to set specially crafted values in one of these environment variables before a ksh shell is executed (either directly or through a script), he could execute arbitrary
http://seclists.org/fulldisclosure/2020/May/53https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14868https://github.com/att/ast/commit/c7de8b641266bac7c77942239ac659edfee9ecd2https://lists.debian.org/debian-lts-announce/2020/07/msg00015.htmlhttps://support.apple.com/kb/HT211170http://seclists.org/fulldisclosure/2020/May/53https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14868https://github.com/att/ast/commit/c7de8b641266bac7c77942239ac659edfee9ecd2https://lists.debian.org/debian-lts-announce/2020/07/msg00015.htmlhttps://support.apple.com/kb/HT211170
2020-04-02
Published