MGASA-2021-0288 - Updated bash packages fix a security vulnerability

Publication date: 28 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0288.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-18276

A privilege escalation vulnerability was found in bash in the way it dropped
privileges when started with an effective user id not equal to the real user
id. Bash may be vulnerable to this flaw if the setuid permission is set and
the owner of the bash program itself is a non-root user. A local attacker
could exploit this flaw to escalate their privileges on the system
(CVE-2019-18276).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28937
- https://access.redhat.com/errata/RHSA-2021:1679
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18276

SRPMS:
- 7/core/bash-4.4-23.1.2.mga7

Mageia 2021-0288: bash security update

A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id

Summary

A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id. Bash may be vulnerable to this flaw if the setuid permission is set and the owner of the bash program itself is a non-root user. A local attacker could exploit this flaw to escalate their privileges on the system (CVE-2019-18276).

References

- https://bugs.mageia.org/show_bug.cgi?id=28937

- https://access.redhat.com/errata/RHSA-2021:1679

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18276

Resolution

MGASA-2021-0288 - Updated bash packages fix a security vulnerability

SRPMS

- 7/core/bash-4.4-23.1.2.mga7

Severity
Publication date: 28 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0288.html
Type: security
CVE: CVE-2019-18276

Related News