(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
1996-09-13T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | bash | ≤ 1.14.6 | Yes |
Application | gnu | bash | 1.14.0 | Yes |
Application | gnu | bash | 1.14.1 | Yes |
Application | gnu | bash | 1.14.2 | Yes |
Application | gnu | bash | 1.14.3 | Yes |
Application | gnu | bash | 1.14.4 | Yes |
Application | gnu | bash | 1.14.5 | Yes |
Application | tcsh | tcsh | 6.05 | Yes |