← Back

CVE-1999-0491

nvd nist
Published: Apr 20, 1999Modified: Apr 16, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

Affected (17)

Products: Gnu: Bash
1 product
Bash
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Up to 2.04
Version 1.14.0
Version 1.14.1
Version 1.14.2
Version 1.14.3
Version 1.14.4
Version 1.14.5
Version 1.14.6
Version 1.14.7
Version 2.01.1
Version 2.01
Version 2.02.1
Version 2.02
Version 2.03
Version 2.05
Version 2.05 a
Version 2.0

References (6)

ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt (unsafe URL)
Source: cve@mitre.org
PatchVendor Advisory
ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.