CVE-2019-14868

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
debiandebian_linux
9.0
applemac_os_x
𝑥
< 10.15.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ksh
bullseye
2020.0.0+really93u+20120801-9
fixed
jessie
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ksh
bionic
needs-triage
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
Fixed 93u+20120801-1ubuntu0.14.04.1+esm1
released
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ksh
RHEL 6
0:20120801-38.el6_10
fixed
RHEL 7
0:20120801-140.el7_7
fixed