[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3035-1 bash -- bash

ID: oval:org.secpod.oval:def:601787Date: (C)2014-10-13   (M)2024-02-19
Class: PATCHFamily: unix




Tavis Ormandy discovered that the patch applied to fix CVE-2014-6271 released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was incomplete and could still allow some characters to be injected into another environment . With this update prefix and suffix for environment variable names which contain shell functions are added as hardening measure. Additionally two out-of-bounds array accesses in the bash parser are fixed which were revealed in Red Hat"s internal analysis for these issues and also independently reported by Todd Sabin.

Platform:
Debian 7.0
Product:
bash
Reference:
DSA-3035-1
CVE-2014-7169
CVE-2014-6271
CVE-2014-6277
CVE-2014-6278
CVE    4
CVE-2014-6277
CVE-2014-6278
CVE-2014-7169
CVE-2014-6271
...
CPE    30
cpe:/o:debian:debian_linux:7.x
cpe:/a:gnu:bash:3.2.48
cpe:/a:gnu:bash:2.05:a
cpe:/a:gnu:bash:2.05:b
...

© SecPod Technologies