Vulnerability Name: | CCN-50300 | ||||||
Published: | 2009-04-14 | ||||||
Updated: | 2009-04-14 | ||||||
Summary: | Fedora bash-completion could provide weaker than expected security, caused by the improper escaping of specific characters. A local attacker could exploit this vulnerability using specially-crafted filenames to trigger malicious completion suggestions. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Other | ||||||
References: | Source: CCN Type: Debian Bug report logs - #259987 bash_completion does not properly quote characters Source: CCN Type: SA34989 Fedora bash-completion Character Escaping Weakness Source: CCN Type: OSVDB ID: 56285 Fedora Linux bash-completion Crafted Character Escaping Local Privilege Escalation Source: CCN Type: FEDORA-2009-3640 bash-completion-1.0-2.fc9 security update Source: XF Type: UNKNOWN bashcompletion-characters-weak-security(50300) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |