CVE-1999-0491

UnknownEPSS 0.86%

Last modified

CVE-1999-0491 is a vulnerability of currently unknown severity. The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.

Description

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

Metrics

EPSS Probability
0.86%

54.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GnuBash<= 2.04
GnuBash1.14.0
GnuBash1.14.1
GnuBash1.14.2
GnuBash1.14.3
GnuBash1.14.4
GnuBash1.14.5
GnuBash1.14.6
GnuBash1.14.7
GnuBash2.0
GnuBash2.01
GnuBash2.01.1
GnuBash2.02
GnuBash2.02.1
GnuBash2.03
GnuBash2.05

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-1999-0491?
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
How severe is CVE-1999-0491?
Severity scoring for CVE-1999-0491 is pending analysis. The EPSS model estimates a 0.86% probability of exploitation in the next 30 days.
How do I fix CVE-1999-0491?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-1999-0491?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST