CVE-2017-5932: Input Validation
Published Mar 27, 2017
·Updated
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Affected Software
1 affected component
GNU Bash=4.4
Remediation
Patch Available
Event History
Mar 27, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5932?
CVE-2017-5932 is considered a high severity vulnerability due to its ability to allow privilege escalation.
2
How do I fix CVE-2017-5932?
To fix CVE-2017-5932, update Bash to version 4.4 or later, or apply security patches provided by your distribution.
3
Who is affected by CVE-2017-5932?
Local users on systems running Bash version 4.4 are affected by CVE-2017-5932.
4
What type of vulnerability is CVE-2017-5932?
CVE-2017-5932 is a privilege escalation vulnerability stemming from improper handling of filenames in Bash.
5
Can CVE-2017-5932 be exploited remotely?
CVE-2017-5932 cannot be exploited remotely as it requires local user access to the system.