CVE-2012-3410

medium
Published 2012-08-27 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.6

Description

Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: secalert@redhat.com โ€” ftp://ftp.gnu.org/pub/gnu/bash/bash-4.2-patches/bash42-033}

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.2-4
debian debianbullseyefixed4.2-4
debian debianforkyfixed4.2-4
debian debiansidfixed4.2-4
debian debiantrixiefixed4.2-4

Application impact

VendorProductVersionsFixed
gnubash4.2

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.