Описание
Security update for bash
This update for bash fixes the following issues:
- CVE-2016-7543: Local attackers could have executed arbitrary commands via specially crafted SHELLOPTS+PS4 variables (bsc#1001299)
- CVE-2016-0634: Malicious hostnames could have allowed arbitrary command execution when $HOSTNAME was expanded in the prompt (bsc#1000396)
- CVE-2014-6277: More troubles with functions (bsc#898812, bsc#1001759)
- CVE-2014-6278: Code execution after original 6271 fix (bsc#898884)
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.1
Ссылки
- E-Mail link for openSUSE-SU-2016:2961-1
- SUSE Security Ratings
Описание
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
Затронутые продукты
Ссылки
- CVE-2014-6277
- SUSE Bug 898664
- SUSE Bug 898762
- SUSE Bug 898812
- SUSE Bug 898884
- SUSE Bug 900057
- SUSE Bug 900127
- SUSE Bug 900454
Описание
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Затронутые продукты
Ссылки
- CVE-2014-6278
- SUSE Bug 898604
- SUSE Bug 898664
- SUSE Bug 898762
- SUSE Bug 898812
- SUSE Bug 898884
- SUSE Bug 900057
- SUSE Bug 900127
Описание
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
Затронутые продукты
Ссылки
- CVE-2016-0634
- SUSE Bug 1000396
- SUSE Bug 1001299
- SUSE Bug 1159416
Описание
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
Затронутые продукты
Ссылки
- CVE-2016-7543
- SUSE Bug 1001299
- SUSE Bug 1159416