Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14868

Опубликовано: 02 апр. 2020
Источник: debian
EPSS Низкий

Описание

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kshfixed2020.0.0-2.1package
kshfixed93u+20120801-3.4+deb10u1busterpackage
kshignoredjessiepackage
ksh93removedpackage

Примечания

  • https://github.com/att/ast/commit/c7de8b641266bac7c77942239ac659edfee9ecd2

EPSS

Процентиль: 42%
0.00204
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 6 лет назад

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

CVSS3: 7.4
redhat
около 6 лет назад

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

CVSS3: 7.4
nvd
почти 6 лет назад

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

suse-cvrf
больше 1 года назад

Security update for ksh

CVSS3: 7.8
github
больше 3 лет назад

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

EPSS

Процентиль: 42%
0.00204
Низкий