First published: Fri Sep 13 1996(Updated: )
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Bash | <=1.14.6 | |
Tcsh Tcsh | =6.05 | |
GNU Bash | =1.14.3 | |
GNU Bash | =1.14.1 | |
GNU Bash | =1.14.2 | |
GNU Bash | =1.14.4 | |
GNU Bash | =1.14.5 | |
GNU Bash | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.