Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:1214-1 Critical Alert for Bash Code Execution Vulnerability

suse
Calendar Grey September 25, 2014
Scroller Suse
Important security patch for SUSE bash resolves two critical vulnerabilities, bolstering defenses against potential exploits and security breaches.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

bash has been updated to fix a critical security issue. In some circumstances, the shell would evaluate shellcode in environment variables passed at startup time. This allowed code execution by local or remote attackers who could pass environment variables to bash scripts. (CVE-2014-6271) Additionally, the following bugs have been fixed: * Avoid possible buffer overflow when expanding the /dev/fd prefix with e.g. the test built-in. (CVE-2012-3410) * Enable workaround for changed behavior of sshd. (bnc#688469) Security Issues: * CVE-2014-6271 * CVE-2012-3410 Package List: - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64): bash-3.1-24.32.1

References

#688469 #770795 #896776

Cross- CVE-2012-3410 CVE-2014-0475

Affected Products:

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2012-3410.html

https://www.suse.com/security/cve/CVE-2014-0475.html

https://bugzilla.suse.com/show_bug.cgi?id=688469

https://bugzilla.suse.com/show_bug.cgi?id=770795

https://bugzilla.suse.com/show_bug.cgi?id=896776

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1214-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.