Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9924

Опубликовано: 07 мар. 2019
Источник: redhat
CVSS3: 7.8

Описание

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

Отчет

Impact of the flaw set to Moderate as restricted shell shall not be used as a security feature alone, as it is very hard to configure it properly and several bypasses exist for it. This issue did not affect the versions of bash as shipped with Red Hat Enterprise Linux 5 as they did not include support for BASH_CMDS environment variable. Red Hat Virtualization Hypervisor and Management Appliance were affected by this issue, but do not use the restricted bash shell in a way that would be exposed to attackers. Future updates may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bashNot affected
Red Hat Enterprise Linux 6bashWill not fix
Red Hat Enterprise Linux 8bashNot affected
Red Hat Virtualization 4redhat-virtualization-hostWill not fix
Red Hat Virtualization 4rhvm-applianceWill not fix
Red Hat Ansible Tower 3.5 for RHEL 7ansible-tower-35/ansible-towerFixedRHBA-2020:153922.04.2020
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHBA-2020:154022.04.2020
Red Hat Enterprise Linux 7bashFixedRHSA-2020:111331.03.2020
Red Hat Enterprise Linux 7.4 Advanced Update SupportbashFixedRHSA-2020:380322.09.2020
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportbashFixedRHSA-2020:380322.09.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1691774bash: BASH_CMD is writable in restricted bash shells

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

CVSS3: 7.8
nvd
почти 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

CVSS3: 7.8
debian
почти 7 лет назад

rbash in Bash before 4.4-beta2 did not prevent the shell user from mod ...

suse-cvrf
почти 7 лет назад

Security update for bash

suse-cvrf
почти 7 лет назад

Security update for bash

7.8 High

CVSS3