CVE-1999-1383
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
- Gnu Bash
- ≤ 1.14.6, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5
- Tcsh
- = 6.05
- Fix
- Available
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2001-09-12
CVE-1999-1383 at NVD
No indexed exploits for CVE-1999-1383 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-1999-1383 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.