Revision Date: | 2015-01-26 | Version: | 4 |
Title: | SUSE-SU-2014:1259-1 -- bash (important) |
Description: | The command-line shell 'bash' evaluates environment variables, whichallows the injection of characters and might be used to access files onthe system in some circumstances (CVE-2014-7169).Please note that this issue is different from a previously fixedvulnerability tracked under CVE-2014-6271 and it is less serious due tothe special, non-default system configuration that is needed to create anexploitable situation.To remove further exploitation potential we now limit thefunction-in-environment variable to variables prefixed with BASH_FUNC_ .This hardening feature is work in progress and might be improved in laterupdates.Additionaly two more security issues were fixed in bash: CVE-2014-7186:Nested HERE documents could lead to a crash of bash.CVE-2014-7187: Nesting of for loops could lead to a crash of bash. |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2014-6271 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 SUSE-SU-2014:1259-1
|
Platform(s): | SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Server 12
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Server 12 and SUSE Linux Enterprise Desktop 12 release section Operation system section
SUSE Linux Enterprise Server 12 is installed
OR SUSE Linux Enterprise Desktop 12 is installed
AND Packages match section
bash-doc is earlier than 0:4.2-81.1
OR readline-doc is earlier than 0:6.2-81.1
SUSE Linux Enterprise Desktop 12 release section
SUSE Linux Enterprise Desktop 12 is installed
AND Packages match section
bash is earlier than 0:4.2-81.1
OR bash-debuginfo is earlier than 0:4.2-81.1
OR bash-debugsource is earlier than 0:4.2-81.1
OR libreadline6 is earlier than 0:6.2-81.1
OR libreadline6-debuginfo is earlier than 0:6.2-81.1
OR bash-lang is earlier than 0:4.2-81.1
|