CVE-2016-0634

The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
gnubash
4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bash
bookworm
5.2.15-2
fixed
bullseye
5.1-2+deb11u1
fixed
sid
5.2.32-1
fixed
trixie
5.2.32-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bash
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
precise
ignored
trusty
Fixed 4.3-7ubuntu1.7
released
xenial
Fixed 4.3-14ubuntu1.2
released
yakkety
Fixed 4.3-15ubuntu1.1
released
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bash
suse enterprise sap 12 SP1
4.2-82.1
fixed
suse enterprise sap 12 SP3
4.3-83.10.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise server 12 SP1
4.2-82.1
fixed
suse enterprise server 12 SP2
4.3-83.10.1
fixed
suse enterprise server 12 SP3
4.3-83.10.1
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
bash-doc
suse enterprise sap 12 SP1
4.2-82.1
fixed
suse enterprise sap 12 SP3
4.3-83.10.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise server 12 SP1
4.2-82.1
fixed
suse enterprise server 12 SP2
4.3-83.10.1
fixed
suse enterprise server 12 SP3
4.3-83.10.1
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
libreadline6
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP3
6.3-83.10.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP2
6.3-83.10.1
fixed
suse enterprise server 12 SP3
6.3-83.10.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
libreadline6-32bit
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP3
6.3-83.10.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP2
6.3-83.10.1
fixed
suse enterprise server 12 SP3
6.3-83.10.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
readline-doc
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP3
6.3-83.10.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP2
6.3-83.10.1
fixed
suse enterprise server 12 SP3
6.3-83.10.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bash
RHEL 6
0:4.1.2-48.el6
fixed
RHEL 7
0:4.2.46-28.el7
fixed
bash-doc
RHEL 6
0:4.1.2-48.el6
fixed
RHEL 7
0:4.2.46-28.el7
fixed
References