First published: Mon Mar 27 2017(Updated: )
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Bash | =4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5932 is considered a high severity vulnerability due to its ability to allow privilege escalation.
To fix CVE-2017-5932, update Bash to version 4.4 or later, or apply security patches provided by your distribution.
Local users on systems running Bash version 4.4 are affected by CVE-2017-5932.
CVE-2017-5932 is a privilege escalation vulnerability stemming from improper handling of filenames in Bash.
CVE-2017-5932 cannot be exploited remotely as it requires local user access to the system.