CVE-2009-0854: OS Command Injection
Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using dash 0.5.4 as a login shell are exposed when a local user can cause a login session to start in a directory containing an attacker-controlled .profile file.
What does an attacker need to exploit it?
The attacker needs local access and the ability to place a Trojan horse .profile file in the current working directory used when the affected dash login shell starts. No authentication is required according to the supplied vector.
Is the default dash configuration affected?
The provided information identifies the vulnerable condition specifically as dash 0.5.4 being used as a login shell. It does not establish whether dash is configured as a login shell by default on a particular system.
What can be done if patching is not immediately possible?
Avoid using the affected dash version as a login shell, and prevent login sessions from starting in directories writable by untrusted users. Review and remove untrusted .profile files from login working directories.