CVE-2012-3410: Buffer Overflow
Published Aug 27, 2012
·Updated
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
Affected Software
1 affected component
GNU Bash=4.2
Remediation
Patch Available
Patch Available
Event History
Aug 27, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3410?
CVE-2012-3410 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-3410?
To fix CVE-2012-3410, update GNU Bash to version 4.2 patch 33 or later.
3
Who is affected by CVE-2012-3410?
Local users on systems running GNU Bash versions prior to 4.2 patch 33 are affected by CVE-2012-3410.
4
What does CVE-2012-3410 exploit?
CVE-2012-3410 exploits a stack-based buffer overflow that allows bypassing restricted shell access.
5
Is CVE-2012-3410 a remote vulnerability?
No, CVE-2012-3410 is a local vulnerability that requires authenticated access to the system.