Information on source package bash

Available versions

ReleaseVersion
jessie4.3-11+deb8u2
stretch4.4-5
buster5.0-4
bullseye5.1-2+deb11u1
bookworm5.2.15-2
trixie5.2.21-2
sid5.2.21-2

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2022-3715fixedfixedfixedvulnerable (no DSA)fixedfixedfixedA flaw was found in the bash package, where a heap-buffer overflow can ...

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
TEMP-0841856-B18BAFvulnerablevulnerablevulnerablevulnerablevulnerablevulnerablevulnerablePrivilege escalation possible to other user than root
CVE-2019-18276vulnerablevulnerablevulnerablefixedfixedfixedfixedAn issue was discovered in disable_priv_mode in shell.c in GNU Bash th ...

Resolved issues

BugDescription
CVE-2019-9924rbash in Bash before 4.4-beta2 did not prevent the shell user from mod ...
CVE-2017-5932The path autocompletion feature in Bash 4.4 allows local users to gain ...
CVE-2016-9401popd in bash might allow local users to bypass the restricted shell an ...
CVE-2016-7543Bash before 4.4 allows local users to execute arbitrary commands with ...
CVE-2016-0634The expansion of '\h' in the prompt string in bash 4.3 allows remote a ...
CVE-2014-7187Off-by-one error in the read_token_word function in parse.y in GNU Bas ...
CVE-2014-7186The redirection implementation in parse.y in GNU Bash through 4.3 bash ...
CVE-2014-7169GNU Bash through 4.3 bash43-025 processes trailing strings after certa ...
CVE-2014-6278GNU Bash through 4.3 bash43-026 does not properly parse function defin ...
CVE-2014-6277GNU Bash through 4.3 bash43-026 does not properly parse function defin ...
CVE-2014-6271GNU Bash through 4.3 processes trailing strings after function definit ...
CVE-2012-6711A heap-based buffer overflow exists in GNU Bash before 4.3 when wide c ...
CVE-2012-3410Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 ...
CVE-2010-0002The /etc/profile.d/60alias.sh script in the Mandriva bash package for ...
CVE-2008-5374bash-doc 3.2 allows local users to overwrite arbitrary files via a sym ...

Security announcements

DSA / DLADescription
ELA-139-1bash - security update
DLA-1726-1bash - security update
ELA-96-1bash - security update
DLA-680-2bash - version number correction
DLA-680-1bash - security update
DLA-63-1bash - security update
DSA-3035-1bash - security update
DSA-3032-1bash - security update
DLA-59-1bash - security update

Search for package or bug name: Reporting problems