| Vulnerability Name: | CVE-1999-0234 (CCN-396) | ||||||||
| Assigned: | 1996-10-01 | ||||||||
| Published: | 1996-10-01 | ||||||||
| Updated: | 2022-08-17 | ||||||||
| Summary: | Bash treats any character with a value of 255 as a command separator. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: CCN Type: CIAC Information Bulletin H-01 Vulnerabilities in bash Source: MITRE Type: CNA CVE-1999-0234 Source: CCN Type: CERT Advisory CA-1996-22 Vulnerabilities in bash Source: CCN Type: CIAC Information Bulletin G-41 A variable declaration error in "bash" allows the character with value 255 decimal to be used as a command separator Source: CCN Type: Geocrawler Web site archives Fix for security problem in bash-1.14.6 Source: CCN Type: OSVDB ID: 11515 Multiple Unix bash 255 Value Command Separator Attack Source: XF Type: UNKNOWN bash-cmd(396) Source: MISC Type: UNKNOWN https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0234 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||