First published: Tue Sep 27 2016(Updated: )
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/bash | <4.4 | 4.4 |
GNU Bash | <=4.3 | |
Fedora | =23 | |
Fedora | =24 | |
Fedora | =25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7543 has been classified as a critical vulnerability due to the potential for local users to execute arbitrary commands with root privileges.
To remediate CVE-2016-7543, upgrade your Bash version to 4.4 or later.
CVE-2016-7543 affects Bash versions before 4.4.
CVE-2016-7543 cannot be exploited remotely as it requires local user access to the system.
CVE-2016-7543 affects several Fedora versions, including 23, 24, and 25, along with other systems running vulnerable Bash versions.