{"id":"CVE-1999-1383","title":"(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell…","summary":"(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell…","severity":"medium","cvss":4.6,"cvssVector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","cwe":["CWE-264"],"published":"1996-09-13","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1383","references":[{"url":"http://marc.info/?l=bugtraq&m=87602167419868&w=2","label":"cve@mitre.org"},{"url":"http://www.dataguard.no/bugtraq/1996_3/0503.html","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=87602167419868&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.dataguard.no/bugtraq/1996_3/0503.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00397,"epssPercentile":0.3367,"ingestedAt":"2026-06-22T15:59:08.100Z","slug":"CVE-1999-1383","body":"## Overview\n\n(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \\w option in the PS1 variable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}