Upstream information
Description
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.NVD CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 770795 SUSE Security Advisories:- openSUSE-SU-2012:0898-1, published Mon, 23 Jul 2012 11:08:40 +0200 (CEST)
