CVE-1999-0491
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
- Affected products
- Bash
- Gnu Bash
- ≤ 2.04, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.14.6, 1.14.7, 2.0, 2.01, 2.01.1, 2.02, 2.02.1, 2.03, 2.05
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2000-06-02
CVE-1999-0491 at NVD
1 known exploit for CVE-1999-0491
Proof-of-concept code and exploit modules indexed by Sploitus