CVE-2012-3410
EPSS 0.41%
描述
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
如何修補 CVE-2012-3410
要修補 CVE-2012-3410,請將受影響套件升級到下列已修補版本。
- Debian/bash—升級至 4.2-4 或更新版本
CVE-2012-3410 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4.2-4