Improper input validation in Bash - CVE-2016-0634

 

Improper input validation in Bash - CVE-2016-0634

Published: May 28, 2018 / Updated: May 31, 2018


Vulnerability identifier: #VU13103
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0634
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.

The vulnerability exists in the expansion of 'h' in the prompt string due to insufficient validation of user-supplied input. A remote attacker can place shell metacharacters in 'hostname' of a machine and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Bash
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
Fedora
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem 900 9840-AE2 and 9843-AE2
bash (Alpine package)
openSUSE Leap
bash (Red Hat package)
bash
IBM BladeCenter Advanced Management Module
IBM SAN Volume Controller
IBM Spectrum Virtualize for Public Cloud
IBM Storwize V3500
IBM Spectrum Virtualize Software
IBM Storwize V3700
IBM FlashSystem V9000
IBM Storwize V7000
IBM Storwize V5000

How to mitigate CVE-2016-0634

Install update from vendor's website.

bash (Alpine package) - update to 4.4.12-r0
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
bash (Red Hat package) - update to 4.1.2-48.el6
bash - addressed in versions 4.3.42-4.fc23, 4.3.42-6.fc24, 4.3.43-3.fc25
IBM SAN Volume Controller - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Spectrum Virtualize for Public Cloud - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V3500 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Spectrum Virtualize Software - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V3700 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM FlashSystem V9000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V7000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1
IBM Storwize V5000 - addressed in versions 7.7.1.9, 7.8.1.6, 8.1.1.2, 8.1.2.1

External References

Related Security Bulletins