mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
793 B
793 B
CVE-2012-3410
Description
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
POC
Reference
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681278
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681278
Github
No PoCs found on GitHub currently.