2.1
CVSSv2

CVE-2010-0002

Published: 14/01/2010 Updated: 08/08/2011
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu bash 3.2

gnu bash 3.2.48

gnu bash 4.0

gnu bash 2.05

gnu bash 3.0

Exploits

source: wwwsecurityfocuscom/bid/37776/info GNU Bash is prone to a command-injection vulnerability because it fails to adequately sanitize control characters in the 'ls' command Attackers can exploit this issue to execute arbitrary commands in a bash terminal; other attacks may also be possible The following example is available: 1 ...