CVE-1999-0234

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Oct 8, 1996
Updated: Nov 20, 2024

Summary

CVE-1999-0234 is a vulnerability affecting the Bash shell. It permits an attacker to inject commands into a shell session by placing a character with a value of 255 as a command separator. This can lead to arbitrary code execution and potential system compromise. Bash interprets such characters as a signal to separate commands, creating a security loophole. Attackers can exploit this issue by sending crafted inputs or modifying shell scripts. This vulnerability, if exploited, can result in serious consequences, including data theft or system takeover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SGI IRAX
  • Red Hat Enterprise Linux
  • SUSE Linux Enterprise Server

Affected Vendors

  • Red Hat
  • SUSE Linux GmbH
  • Saskatchewan Government Insurance