CVE-2017-5932

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gnubash
4.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bash
bookworm
5.2.15-2
fixed
bullseye
5.1-2+deb11u1
fixed
jessie
not-affected
sid
5.2.32-1
fixed
trixie
5.2.32-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bash
precise
not-affected
trusty
not-affected
xenial
not-affected
yakkety
not-affected
zesty
Fixed 4.4-2ubuntu1.1
released