Vulnerability Details CVE-2012-6711
A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.4%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 4.6
Products affected by CVE-2012-6711
-
-
cpe:2.3:a:gnu:bash:4.2.53
-
-
cpe:2.3:o:redhat:enterprise_linux:7.0