CVE-2016-7543
UnknownEPSS 0.58%
Last modified
CVE-2016-7543 is a vulnerability of currently unknown severity. Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Bash | <= 4.3 |
| Fedoraproject | Fedora | 23 |
| Fedoraproject | Fedora | 24 |
| Fedoraproject | Fedora | 25 |
References
- http://www.openwall.com/lists/oss-security/2016/09/26/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93183Third Party Advisory, VDB Entry
- https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201701-02Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/26/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/93183Third Party Advisory, VDB Entry
- https://lists.gnu.org/archive/html/bug-bash/2016-09/msg00018.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201701-02Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7543?
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
How severe is CVE-2016-7543?
Severity scoring for CVE-2016-7543 is pending analysis. The EPSS model estimates a 0.58% probability of exploitation in the next 30 days.
How do I fix CVE-2016-7543?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-7537MagickCore/memory.c in ImageMagick allows remote attackers t…6.5
- CVE-2016-7538coders/psd.c in ImageMagick allows remote attackers to cause…6.5
- CVE-2016-7539Memory leak in AcquireVirtualMemory in ImageMagick before 7 …
- CVE-2016-7540coders/rgf.c in ImageMagick before 6.9.4-10 allows remote at…
- CVE-2016-7541Long lived sessions in Fortinet FortiGate devices with Forti…
- CVE-2016-7542A read-only administrator on Fortinet devices with FortiOS 5…
- CVE-2016-7544Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _mal…
- CVE-2016-7545SELinux policycoreutils allows local users to execute arbitr…
- CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery…
- CVE-2016-7549Google Chrome before 53.0.2785.113 does not ensure that the …
- CVE-2016-7550asterisk 13.10.0 is affected by: denial of service issues in…
- CVE-2016-7551chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13…
Are you affected by CVE-2016-7543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
