CVE-1999-1048 describes a buffer overflow vulnerability in various versions of Bash, including 2.0.0 and 1.4.17, affecting Debian and Red Hat Linux distributions. A local attacker can exploit this by creating an excessively long directory name, which, when displayed in the password prompt via the PS1 environmental variable, triggers the overflow and allows for privilege escalation. The vulnerability has a medium severity CVSS score of 4.6, indicating low attack complexity and potential for partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:1.3.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:o:redhat:linux:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.