← Back

CVE-1999-1383

nvd nist
Published: Sep 13, 1996Modified: Apr 16, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.

Affected (8)

Products: Gnu: Bash · Tcsh: Tcsh
1 product
Bash
1 product
Tcsh
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Up to 1.14.6
Version 1.14.0
Version 1.14.1
Version 1.14.2
Version 1.14.3
Version 1.14.4
Version 1.14.5
Version 6.05

Related CWEs

References (4)

Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory

Timeline

No history available yet.