GNU Bash OS Command Injection sérülékenysége
Angol cím: GNU Bash OS Command Injection Vulnerability
Publikálás dátuma: 2025.10.07.
Utolsó módosítás dátuma: 2025.10.07.
Leírás
A program nem, vagy helytelenül semlegesíti azokat az elemeket a bemenetből, melyek módosíthatják a tervezett operációs rendszer parancsot, amikor azt a következő komponensnek küldi.
Leírás forrása: CWE-78 Leírás utolsó módosítása: 2025.09.09.Elemzés leírás
Eredeti nyelven:
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.
Hatás
CVSS3.1 Súlyosság és Metrika
Base score: 8.8 (Magas)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope (S): Unchanged
Confidentiality Impact (C): High
Integrity Impact (I): High
Availability Impact (A): High
Sérülékeny szoftverek
cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:1.14.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.01:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.01.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.02:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.02.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.03:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.04:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.05:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.05:a:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:2.05:b:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:3.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:3.0.16:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:3.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:3.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:3.2.48:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:4.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:4.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:4.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:bash:4.3:*:*:*:*:*:*:*
