CVE-1999-0491

GNU Bash < 2.04 - Code Injection

Title source: rule
STIX 2.1

Description

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shadow · textlocallinux
https://www.exploit-db.com/exploits/19095

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_caldera
ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/119

Scores

EPSS 0.0030
EPSS Percentile 53.3%

Details

CWE
CWE-94
Status published
Products (16)
gnu/bash 1.14.0
gnu/bash 1.14.1
gnu/bash 1.14.2
gnu/bash 1.14.3
gnu/bash 1.14.4
gnu/bash 1.14.5
gnu/bash 1.14.6
gnu/bash 1.14.7
gnu/bash 2.0
gnu/bash 2.01
... and 6 more
Published Apr 20, 1999
Tracked Since Feb 18, 2026