Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:1212-1 Critical: Bash Code Execution Advisory

suse
Calendar Grey September 25, 2014
Scroller Suse
SUSE Security Patch for curl fixes severe vulnerability that permits remote code execution through user input.
An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is ...

Summary

bash has been updated to fix a critical security issue. In some circumstances, the shell would evaluate shellcode in environment variables passed at startup time. This allowed code execution by local or remote attackers who could pass environment variables to bash scripts. (CVE-2014-6271) Additionally, the following bugs have been fixed: * Fix crash when expanding '$[' without matching ']'. (bnc#844550) * Do not restart the signal handler after a trap is reset. (bnc#820149) * Work around a crash in libreadline. (bnc#819783) * Make skeleton files configurations files. (bnc#776694) Security Issues: * CVE-2014-6271 Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#776694 #819783 #820149 #844550 #896776

Cross- CVE-2014-0475

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2014-0475.html

https://bugzilla.suse.com/show_bug.cgi?id=776694

https://bugzilla.suse.com/show_bug.cgi?id=819783

https://bugzilla.suse.com/show_bug.cgi?id=820149

https://bugzilla.suse.com/show_bug.cgi?id=844550

https://bugzilla.suse.com/show_bug.cgi?id=896776

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1212-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.