Oval Definition:oval:org.mitre.oval:def:26821
Revision Date:2014-11-10Version:5
Title:SUSE-SU-2014:1214-1 -- Security update for bash
Description:ash has been updated to fix a critical security issue.In some circumstances, the shell would evaluate shellcode in environmentvariables passed at startup time. This allowed code execution by local orremote attackers who could pass environment variables to bash scripts.(CVE-2014-6271)Additionally, the following bugs have been fixed: * Avoid possible buffer overflow when expanding the /dev/fd prefix with e.g. the test built-in. (CVE-2012-3410) * Enable workaround for changed behavior of sshd. (bnc#688469)Security Issues: * CVE-2014-6271 * CVE-2012-3410
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-3410
CVE-2014-0475
CVE-2014-6271
SUSE-SU-2014:1214-1
Platform(s):SUSE Linux Enterprise Server 10
Product(s):bash
Definition Synopsis
  • SUSE Linux Enterprise Server 10 is installed
  • AND Packages match section
  • bash RPM is earlier than 0:3.1-24.32.1
  • OR readline RPM is earlier than 0:5.1-24.32.1
  • OR readline-devel RPM is earlier than 0:5.1-24.32.1
  • OR readline-32bit RPM is earlier than 0:5.1-24.32.1
  • OR readline-devel-32bit RPM is earlier than 0:5.1-24.32.1
  • BACK