CVE-2016-7543

HIGH

GNU Bash < 4.3 - Improper Input Validation

Title source: rule

Description

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

Scores

CVSS v3 8.4
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status draft

Affected Products (4)

gnu/bash < 4.3
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora

Timeline

Published Jan 19, 2017
Tracked Since Feb 18, 2026