CVE-2016-7543

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2017-0725.html
http://www.openwall.com/lists/oss-security/2016/09/26/9 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/93183 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037812
https://access.redhat.com/errata/RHSA-2017:1931
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/
https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.html Patch Vendor Advisory
https://security.gentoo.org/glsa/201701-02 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0725.html
http://www.openwall.com/lists/oss-security/2016/09/26/9 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/93183 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037812
https://access.redhat.com/errata/RHSA-2017:1931
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/
https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.html Patch Vendor Advisory
https://security.gentoo.org/glsa/201701-02 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:bash:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

History

21 Nov 2024, 02:58

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2017-0725.html - () http://rhn.redhat.com/errata/RHSA-2017-0725.html -
References () http://www.openwall.com/lists/oss-security/2016/09/26/9 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/09/26/9 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/93183 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/93183 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037812 - () http://www.securitytracker.com/id/1037812 -
References () https://access.redhat.com/errata/RHSA-2017:1931 - () https://access.redhat.com/errata/RHSA-2017:1931 -
References () https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115 - () https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05388115 -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/ -
References () https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.html - Patch, Vendor Advisory () https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.html - Patch, Vendor Advisory
References () https://security.gentoo.org/glsa/201701-02 - Third Party Advisory () https://security.gentoo.org/glsa/201701-02 - Third Party Advisory

07 Nov 2023, 02:34

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/', 'name': 'FEDORA-2016-5a54fb4784', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/', 'name': 'FEDORA-2016-f84391516d', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/', 'name': 'FEDORA-2016-2c4b5ad64e', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU3C756YPHDAAPFX76UGZBAQQQ5UMHS5/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7XOQSHU63Y357NHU5FPTFBM6I3YOCQB/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2VRBSIPZDZ75ZQ2DLITHUIDW4W26KVR/ -

Information

Published : 2017-01-19 20:59

Updated : 2024-11-21 02:58


NVD link : CVE-2016-7543

Mitre link : CVE-2016-7543

CVE.ORG link : CVE-2016-7543


JSON object : View

Products Affected

fedoraproject

  • fedora

gnu

  • bash
CWE
CWE-20

Improper Input Validation