Vulnerability Description
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Bash | < 4.4 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 42.3 |
| Netapp | Hci Management Node | - |
| Netapp | Solidfire | - |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://git.savannah.gnu.org/cgit/bash.git/tree/CHANGES?h=bash-4.4-testing#n65Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00049.htmlMailing ListThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/bash/+bug/1803441Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00028.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190411-0001/Third Party Advisory
- https://usn.ubuntu.com/4058-1/Third Party Advisory
- https://usn.ubuntu.com/4058-2/Third Party Advisory
- http://git.savannah.gnu.org/cgit/bash.git/tree/CHANGES?h=bash-4.4-testing#n65Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00049.htmlMailing ListThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/bash/+bug/1803441Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00028.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190411-0001/Third Party Advisory
- https://usn.ubuntu.com/4058-1/Third Party Advisory
- https://usn.ubuntu.com/4058-2/Third Party Advisory
FAQ
What is CVE-2019-9924?
CVE-2019-9924 is a vulnerability with a CVSS score of 7.8 (HIGH). rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
How severe is CVE-2019-9924?
CVE-2019-9924 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9924?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Bash, Debian Debian Linux, Opensuse Leap, Netapp Hci Management Node, Netapp Solidfire.