Vulnerability Name: | CVE-2010-0002 (CCN-55669) | ||||||||
Assigned: | 2009-12-14 | ||||||||
Published: | 2010-01-14 | ||||||||
Updated: | 2011-08-08 | ||||||||
Summary: | The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P) 1.8 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:H/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0002 Source: CCN Type: GNU Project Web site Bash Source: MANDRIVA Type: Patch, Vendor Advisory MDVSA-2010:004 Source: CCN Type: OSVDB ID: 61790 Bash on Mandriva etc/profile.d/60alias.sh LS_OPTIONS Terminal Emulator Escape Sequence Weakness Source: CCN Type: BID-37776 GNU Bash 'ls' Control Character Command Injection Vulnerability Source: XF Type: UNKNOWN bash-60alias-command-execution(55669) Source: CCN Type: Bugzilla Bug 56882 ls should not "show-control-chars" by default Source: CONFIRM Type: UNKNOWN https://qa.mandriva.com/show_bug.cgi?id=56882 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |