4.6

CVE-1999-0491

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Bash Version <= 2.04
Gnu ≫ Bash Version 1.14.0
Gnu ≫ Bash Version 1.14.1
Gnu ≫ Bash Version 1.14.2
Gnu ≫ Bash Version 1.14.3
Gnu ≫ Bash Version 1.14.4
Gnu ≫ Bash Version 1.14.5
Gnu ≫ Bash Version 1.14.6
Gnu ≫ Bash Version 1.14.7
Gnu ≫ Bash Version 2.0
Gnu ≫ Bash Version 2.01
Gnu ≫ Bash Version 2.01.1
Gnu ≫ Bash Version 2.02
Gnu ≫ Bash Version 2.02.1
Gnu ≫ Bash Version 2.03
Gnu ≫ Bash Version 2.05
Gnu ≫ Bash Version 2.05 Update a
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.87% 0.538
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt
Patch
Vendor Advisory
http://www.securityfocus.com/bid/119
http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.9904202114070.6623-100000%40smooth.Operator.org