CVE-2012-3410

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
27 August 2012

Summary

Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.