Bug 36240 - bash: Missing sanitising (2.4)
bash: Missing sanitising (2.4)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 2.4
Other Linux
: P3 normal (vote)
: UCS 2.4-sec10
Assigned To: Security maintainers
Philipp Hahn
:
Depends on: 36005
Blocks:
  Show dependency treegraph
 
Reported: 2014-10-21 08:00 CEST by Tim Petersen
Modified: 2014-10-29 17:13 CET (History)
4 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Petersen univentionstaff 2014-10-21 08:00:20 CEST
+++ This bug was initially created as a clone of Bug #36005 +++

Please make a backport for UCS 2.4.

+++ This bug was initially created as a clone of Bug #35992 +++

CVE-2014-6271

Stephane Chazelas discovered a vulnerability in bash, the GNU
Bourne-Again Shell, related to how environment variables are
processed.  In many common configurations, this vulnerability is
exploitable over the network, especially if bash has been configured
as the system shell.

Additional writeup: 
https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/


Reported at #2014102021000351

I suppose Patches for CVE-2014-6277, CVE-2014-6278, CVE-2014-7186 and CVE-2014-7187 were not included here.

Please assess the severity for these.
Comment 1 Janek Walkenhorst univentionstaff 2014-10-23 19:08:38 CEST
Upstream patches #54…#57 for CVE-2014-{7186,7187,6277,6278} added.
Tests (i386): OK
Comment 2 Philipp Hahn univentionstaff 2014-10-24 02:29:49 CEST
FIXED: b24-scope sec2.4-10 bash # amd64 3.2-4.{45.201409261641→49.201410231847}
OK: apt-get install bash=3.2-4.49.201410231847
OK: env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
OK: /usr/share/doc/bash/changelog.Debian.gz
OK: i386 amd64