4.6
CVSSv2

CVE-2017-5932

Published: 27/03/2017 Updated: 31/03/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu bash 4.4

Vendor Advisories

Several security issues were fixed in Bash ...
The path autocompletion feature in Bash 44 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter ...