← Back

CVE-2019-18276

nvd nist
Published: Nov 28, 2019Modified: Jun 9, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.

Affected (19)

1 product
Bash
3 products
Hci Management Node
Oncommand Unified Manager
Solidfire
1 product
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Up to 5.0
Version 5.0 beta1
Version 5.0 beta2
Version 5.0 patch10
Version 5.0 patch11
Version 5.0 patch1
Version 5.0 patch2
Version 5.0 patch3
Version 5.0 patch4
Version 5.0 patch5
Version 5.0 patch6
Version 5.0 patch7
Version 5.0 patch8
Version 5.0 patch9
Version 5.0 rc1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
From 9.5
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.14.0

References (14)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.