The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:28
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/119 - | |
References | () http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.9904202114070.6623-100000%40smooth.Operator.org - |
07 Nov 2023, 01:54
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 1999-04-20 04:00
Updated : 2024-11-20 23:28
NVD link : CVE-1999-0491
Mitre link : CVE-1999-0491
CVE.ORG link : CVE-1999-0491
JSON object : View
Products Affected
gnu
- bash
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')