Description: | ash has been updated to fix a critical security issue.In some circumstances, the shell would evaluate shellcode in environmentvariables passed at startup time. This allowed code execution by local orremote attackers who could pass environment variables to bash scripts.(CVE-2014-6271)Additionally, the following bugs have been fixed: * Avoid possible buffer overflow when expanding the /dev/fd prefix with e.g. the test built-in. (CVE-2012-3410) * Enable workaround for changed behavior of sshd. (bnc#688469)Security Issues: * CVE-2014-6271 * CVE-2012-3410 |