cbcvebase.
CVE-2019-9924
published 2019-03-22

CVE-2019-9924: rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbash< bash 4.4-1 (bookworm)bash 4.4-1 (bookworm)
debiandebian_linux
gnubash< 4.44.4
gnubash
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
gnubash>= 0 < 4.4-14.4-1
opensuseleap

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH