High severity7.8NVD Advisory· Published Mar 27, 2017· Updated May 13, 2026
CVE-2017-5932
CVE-2017-5932
Description
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- git.savannah.gnu.org/cgit/bash.git/commit/nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2017/02/08/3nvdMailing ListPatchThird Party Advisory
- lists.gnu.org/archive/html/bug-bash/2017-01/msg00034.htmlnvdMailing ListPatchVendor Advisory
- www.securityfocus.com/bid/96136nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.