CVE-2012-3410

GNU Bash - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.

Scores

EPSS 0.0008
EPSS Percentile 24.2%

Classification

CWE
CWE-119
Status draft

Affected Products (1)

gnu/bash

Timeline

Published Aug 27, 2012
Tracked Since Feb 18, 2026