Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE 12.3: 2014:1229-1 Important Bash Multiple Issues Fixed

opensuse
Calendar Grey September 28, 2014
Dist Opensuse Esm H88
This modification tackles significant concerns in shell for Fedora, improving general platform safety.
An update that fixes three vulnerabilities is now available

Description

The command-line shell 'bash' evaluates environment variables, which

allows the injection of characters and might be used to access files on

the system in some circumstances (CVE-2014-7169).

Please note that this issue is different from a previously fixed

vulnerability tracked under CVE-2014-6271 and it is less serious due to

the special, non-default system configuration that is needed to create an

exploitable situation.

To remove further exploitation potential we now limit the

function-in-environment variable to variables prefixed with BASH_FUNC_ .

This hardening feature is work in progress and might be improved in later

updates.

Additionaly two more security issues were fixed in bash: CVE-2014-7186:

Nested HERE documents could lead to a crash of bash.

CVE-2014-7187: Nesting of for loops could lead to a crash of bash.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2014-563

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (i586 x86_64):

bash-4.2-61.15.1

bash-debuginfo-4.2-61.15.1

bash-debugsource-4.2-61.15.1

bash-devel-4.2-61.15.1

bash-loadables-4.2-61.15.1

bash-loadables-debuginfo-4.2-61.15.1

libreadline6-6.2-61.15.1

libreadline6-debuginfo-6.2-61.15.1

readline-devel-6.2-61.15.1

- openSUSE 12.3 (x86_64):

bash-debuginfo-32bit-4.2-61.15.1

libreadline6-32bit-6.2-61.15.1

libreadline6-debuginfo-32bit-6.2-61.15.1

readline-devel-32bit-6.2-61.15.1

- openSUSE 12.3 (noarch):

bash-doc-4.2-61.15.1

bash-lang-4.2-61.15.1

readline-doc-6.2-61.15.1

References

https://www.suse.com/security/cve/CVE-2014-7169.html

https://www.suse.com/security/cve/CVE-2014-7186.html

https://www.suse.com/security/cve/CVE-2014-7187.html

https://bugzilla.suse.com/show_bug.cgi?id=898346

https://bugzilla.suse.com/show_bug.cgi?id=898603

https://bugzilla.suse.com/show_bug.cgi?id=898604

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:1229-1
Rating: important
Affected Products: openSUSE 12.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here