Out-of-bounds read In bash
Description
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 4.3-9.2 | ||
debian 14 | 4.3-9.2 | ||
debian 13 | 4.3-9.2 | ||
debian 11 | 4.3-9.2 | ||
rpm rhel6 | 0:4.1.2-15.el6_5.2 | ||
rpm rhel6 | - | - | |
rpm rhel6.4 | 0:4.1.2-15.el6_4.2 | ||
rpm rhel5 | 0:3.2-33.el5_11.4 | ||
rpm rhel5.9 | 0:3.2-32.el5_9.3 | ||
rpm rhel7 | 0:4.2.45-5.el7_0.4 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5.
References
1. 2.