Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9924

Опубликовано: 07 мар. 2019
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

Отчет

Impact of the flaw set to Moderate as restricted shell shall not be used as a security feature alone, as it is very hard to configure it properly and several bypasses exist for it. This issue did not affect the versions of bash as shipped with Red Hat Enterprise Linux 5 as they did not include support for BASH_CMDS environment variable. Red Hat Virtualization Hypervisor and Management Appliance were affected by this issue, but do not use the restricted bash shell in a way that would be exposed to attackers. Future updates may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bashNot affected
Red Hat Enterprise Linux 6bashWill not fix
Red Hat Enterprise Linux 8bashNot affected
Red Hat Virtualization 4redhat-virtualization-hostWill not fix
Red Hat Virtualization 4rhvm-applianceWill not fix
Red Hat Ansible Tower 3.5 for RHEL 7ansible-tower-35/ansible-towerFixedRHBA-2020:153922.04.2020
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHBA-2020:154022.04.2020
Red Hat Enterprise Linux 7bashFixedRHSA-2020:111331.03.2020
Red Hat Enterprise Linux 7.4 Advanced Update SupportbashFixedRHSA-2020:380322.09.2020
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportbashFixedRHSA-2020:380322.09.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1691774bash: BASH_CMD is writable in restricted bash shells

EPSS

Процентиль: 34%
0.00415
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

CVSS3: 7.8
nvd
больше 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

CVSS3: 7.8
debian
больше 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from mod ...

suse-cvrf
больше 7 лет назад

Security update for bash

suse-cvrf
больше 7 лет назад

Security update for bash

EPSS

Процентиль: 34%
0.00415
Низкий

7.8 High

CVSS3