bash: heap-based buffer overflow during echo of unsupported characters
Published Jun 18, 2019
7.8
HIGHCVSS 3.0
EPSS 0.51%
Description
A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().
Affected products
No data.
Configuration 2
- 7.0
No data.
Red Hat Enterprise Linux 5
bash
Not affected
Red Hat Enterprise Linux 6
bash
Not affected
Red Hat Enterprise Linux 7
bash
Will not fix
Red Hat Enterprise Linux 8
bash
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bash | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bash | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bash | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | bash | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Impact set to Moderate as the flaw requires the usage of `echo -e` built-in function with a string controlled by the attacker. Abusing this flaw would allow an attacker to, at most, execute code with the privileges of the bash process, which could be used e.g. to escape a restricted shell in case of a local attacker scenario or remotely execute code in case of a bash script that accepts untrusted input from the network. However we do not recommend to use bash scripts to handle untrusted data from the network.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 other sources (MITRE, Red Hat) ▾
CVSS:3.0/AC:H/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.51% (0.00510) | 41.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.49% (0.00491) | 38.09th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00081) | 21.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.50% (0.01505) | 73.58th | v2 (v2022.01.01) |
| Mar 3, 2023 | 1.50% (0.01505) | 73.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.50% (0.01505) | 71.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.50% (0.01505) | 50.63th | v2 (v2022.01.01) |
References (9)
- http://git.savannah.gnu.org/cgit/bash.git/commit/?h=devel&id=863d31ae775d56b785dc5b0105b6d251515d81d5 x_refsource_MISCMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/108824 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2012-6711 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1721071 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-6711
- https://support.f5.com/csp/article/K05122252 x_refsource_CONFIRM
- https://support.f5.com/csp/article/K05122252?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4180-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2012-6711
| Link | Providers | Tags |
|---|---|---|
| http://git.savannah.gnu.org/cgit/bash.git/commit/?h=devel&id=863d31ae775d56b785dc5b0105b6d251515d81d5 | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| http://www.securityfocus.com/bid/108824 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2012-6711 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1721071 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2012-6711 | ||
| https://support.f5.com/csp/article/K05122252 | x_refsource_CONFIRM | |
| https://support.f5.com/csp/article/K05122252?utm_source=f5support&%3Butm_medium=RSS | x_refsource_CONFIRM | |
| https://usn.ubuntu.com/4180-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2012-6711 |
Change history (0)
No recorded changes yet.