SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14868

An attacker could use this flaw to override or bypass environment restrictions to execute shell commands.

HIGH 7.8EPSS 1.39%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.39% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
ksh project/ksh · debian/debian linux · apple/mac os x
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.