rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
References
Link | Resource |
---|---|
http://git.savannah.gnu.org/cgit/bash.git/tree/CHANGES?h=bash-4.4-testing#n65 | Vendor Advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00049.html | Mailing List Third Party Advisory |
https://bugs.launchpad.net/ubuntu/+source/bash/+bug/1803441 | Issue Tracking Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2019/03/msg00028.html | Third Party Advisory Mailing List |
https://security.netapp.com/advisory/ntap-20190411-0001/ | Third Party Advisory |
https://usn.ubuntu.com/4058-1/ | Third Party Advisory |
https://usn.ubuntu.com/4058-2/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-03-22T07:05:28
Updated: 2019-08-05T17:06:08
Reserved: 2019-03-22T00:00:00
Link: CVE-2019-9924
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-03-22T08:29:00.467
Modified: 2022-04-05T20:11:00.320
Link: CVE-2019-9924
JSON object: View
Redhat Information
No data.
CWE