1 results (0.005 seconds)
CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

CVE-2019-14868 – ksh: certain environment variables interpreted as arithmetic expressions on startup, leading to code injection
https://notcve.org/view.php?id=CVE-2019-14868
05 Feb 2020 — In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely. En ksh versión 20120801, se detectó un fallo en la manera que evalúa determinadas variables de entorno. Un atacante podría usar este fallo para ... • http://seclists.org/fulldisclosure/2020/May/53 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •