Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 7: 2021-0288 Moderate: Bash Privilege Escalation Threat

mageia
Calendar Grey June 28, 2021
Dist Mageia Esm H88
Recent updates to bash packages in Mageia fix a security vulnerability that permits local users to elevate their privileges via exploitation methods.
A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id

Summary

A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id. Bash may be vulnerable to this flaw if the setuid permission is set and the owner of the bash program itself is a non-root user. A local attacker could exploit this flaw to escalate their privileges on the system (CVE-2019-18276).

References

- https://bugs.mageia.org/show_bug.cgi?id=28937

- https://access.redhat.com/errata/RHSA-2021:1679

- https://www.cve.org/CVERecord?id=CVE-2019-18276

Resolution

SRPMS

- 7/core/bash-4.4-23.1.2.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 28 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0288.html
Type: security
CVE: CVE-2019-18276

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here