Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-6711

Опубликовано: 18 июн. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 7

Описание

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().

РелизСтатусПримечание
bionic

not-affected

4.4.18-2ubuntu1.1
cosmic

not-affected

devel

not-affected

disco

not-affected

eoan

not-affected

esm-infra-legacy/trusty

not-affected

4.3.7ubuntu1.8
esm-infra/bionic

not-affected

4.4.18-2ubuntu1.1
esm-infra/xenial

not-affected

4.3-14ubuntu1.3
precise/esm

not-affected

4.2-2ubuntu2.9
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 34%
0.00139
Низкий

4.6 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
больше 6 лет назад

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().

CVSS3: 7
nvd
больше 6 лет назад

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().

CVSS3: 7
debian
больше 6 лет назад

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide c ...

suse-cvrf
около 6 лет назад

Security update for bash

CVSS3: 7.8
github
почти 4 года назад

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().

EPSS

Процентиль: 34%
0.00139
Низкий

4.6 Medium

CVSS2

7 High

CVSS3