OS Command Injection in KornShell - CVE-2019-14868
Published: February 24, 2020
Vulnerability identifier: #VU25547
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14868
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists in the way ksh evaluates certain environment variables . A local user can set a specially crafted environment variable and execute arbitrary OS commands on the target system.
Affected software
KornShell
Arch Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
CentOS
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openEuler
Fedora
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
ksh (Red Hat package)
ksh-devel
ksh
ksh-debugsource
ksh-debuginfo
ksh-help
Arch Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
CentOS
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openEuler
Fedora
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
ksh (Red Hat package)
ksh-devel
ksh
ksh-debugsource
ksh-debuginfo
ksh-help
How to mitigate CVE-2019-14868
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
ksh (Red Hat package) - addressed in versions 20120801-26.el7_2, 20120801-27.el7_3, 20120801-36.el7_4, 20120801-38.el6_10, 20120801-138.el7_5, 20120801-140.el7_6, 20120801-253.el8_0
ksh-devel - update to 93vu-19.3.2
ksh - update to 93vu-19.3.2
ksh-debugsource - update to 93vu-19.3.2
ksh-debuginfo - update to 93vu-19.3.2
ksh - addressed in versions 2020.0.0-2.fc30, 2020.0.0-2.fc31
ksh-debuginfo - update to 2020.0.0-3
ksh-help - update to 2020.0.0-3
ksh-debugsource - update to 2020.0.0-3
ksh - update to 2020.0.0-3
ksh-devel - update to 93vu-19.3.2
ksh - update to 93vu-19.3.2
ksh-debugsource - update to 93vu-19.3.2
ksh-debuginfo - update to 93vu-19.3.2
ksh - addressed in versions 2020.0.0-2.fc30, 2020.0.0-2.fc31
ksh-debuginfo - update to 2020.0.0-3
ksh-help - update to 2020.0.0-3
ksh-debugsource - update to 2020.0.0-3
ksh - update to 2020.0.0-3
External References
Related Security Bulletins
- Command injectin in KornShell (ksh)
- Red Hat update for ksh
- Red Hat update for ksh
- Arch Linux update for ksh
- CentOS 7 update for ksh
- CentOS 6 update for ksh
- Red Hat Enterprise Linux 7 update for ksh
- Red Hat Enterprise Linux 7 update for ksh
- Red Hat Enterprise Linux 7 update for ksh
- Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions update for ksh
- Red Hat Enterprise Linux 6 update for ksh
- Red Hat Enterprise Linux 7.3 Advanced Update Support update for ksh
- Red Hat Enterprise Linux 7.2 Advanced Update Support update for ksh
- openEuler 20.03 LTS update for ksh-2020.0.0-3
- SUSE update for ksh
- Fedora 30 update for ksh
- Fedora 31 update for ksh