Command injection in Bash - CVE-2016-7543

 

Command injection in Bash - CVE-2016-7543

Published: May 28, 2018 / Updated: May 31, 2018


Vulnerability identifier: #VU13104
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7543
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary commands on the target system.

The weakness exists due to insufficient validation of user-supplied input. A local attacker can supply specially crafted SHELLOPTS and PS4 environment variables, inject and execute arbitrary commands with root privileges.

Affected software

Bash
FlashSystem 900 9840-AE2 and 9843-AE2
PowerScale OneFS
FlashSystem 840 9840-AE1 & 9843-AE1
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Ubuntu
Slackware Linux
Fedora
bash (Alpine package)
openSUSE Leap
bash (Red Hat package)
bash
IBM BladeCenter Advanced Management Module

How to mitigate CVE-2016-7543

Update to version 4.4.

bash (Alpine package) - update to 4.3.30-r1
PowerScale OneFS - addressed in versions 9.1.0.21, 9.2.1.14, 9.3.0.7, 9.4.0.4
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
bash (Red Hat package) - update to 4.1.2-48.el6
bash - addressed in versions 4.3.42-5.fc23, 4.3.42-7.fc24, 4.3.43-4.fc25

External References

Related Security Bulletins