Saturday, September 27, 2014

[USN-2364-1] Bash vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUJn/NAAoJEGVp2FWnRL6TeZIP/3L+cWuZ3KEKNkxPSiEr3C/+
iQffK/QfnVW7OtQodOqvKWhy2ftSWOEkwDnuN+Kw3kIinpepqfAr9m7PstXp3/UW
2WQLvrMUk+3i2vwtLmwuDq9pKQZr1/HRh04RDMsf6r1aspoN4VprA0UWyl9ZvhPc
Afew1NMfSWAwOhpeQPuXzh3962iq7Is2KsQMVRWfr8euqZqfgoeU93rdExHtZVDy
qZEfCjoUzDHinfKbzEt8TwSIULNPOY1bzDK7GrVHIYVDeLUeuRrp/6+wNudHBwic
vyGnOZEdoabLoB9kwJcL5i652B/L5Fcd5uQNRlfZKU6aapTLCoGwiG5Nz7iIAbcu
Z9xtqj7FkvsIAqm7j8VWibxw5NE3RFURktonHfNfh8XZ9dPwGi7J67UEOLN0xkae
8/bE9e7ePhPV4L/XSnVU2oQsKTDk2mAggBopB3ePoFibTJ8zVSb4g74KUpemRU0S
qRVAEuTwN1B12mDCeU2UcqpuIgeAC6IIrEnM+J6CKyoijvylIwYre5NhF3zlcgA9
FHkAP8MibEEWXaytRlPfArGiKw9NPQBGEM4LiYGin7r7bGakpIwYlzPXH8k1f0qv
tKeDKI+dvI74v83W4JOrANaoDn1tkeVGTmL3QEuecCLK9itLpZfv+HFxOnZEO9QR
j/AJU8vvfm2HF+FwC6um
=6T2i
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2364-1
September 27, 2014

bash vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in Bash.

Software Description:
- bash: GNU Bourne Again SHell

Details:

Florian Weimer and Todd Sabin discovered that the Bash parser incorrectly
handled memory. An attacker could possibly use this issue to bypass certain
environment restrictions and execute arbitrary code. (CVE-2014-7186,
CVE-2014-7187)

In addition, this update introduces a hardening measure which adds prefixes
and suffixes around environment variable names which contain shell
functions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
bash 4.3-7ubuntu1.4

Ubuntu 12.04 LTS:
bash 4.2-2ubuntu2.5

Ubuntu 10.04 LTS:
bash 4.1-2ubuntu3.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2364-1
CVE-2014-7186, CVE-2014-7187

Package Information:
https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.4
https://launchpad.net/ubuntu/+source/bash/4.2-2ubuntu2.5
https://launchpad.net/ubuntu/+source/bash/4.1-2ubuntu3.4

No comments:

Post a Comment