CVE-2012-3410

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
27/08/2012
Last modified:
11/04/2025

Description

Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:bash:4.2:*:*:*:*:*:*:*