Monday, March 18, 2024

[USN-6697-1] Bash vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmX4Vb8ACgkQZWnYVadE
vpOL4w/9Gc6RGk93CMDiWRi62KAG8VUSUtOR8a1p+UwRCDPsXFpKCAmb54p/q6L+
Zf9NKryuW+skltgqX5L0VcU9Lq9qtoDOaFn47BUWbm+YGod9fI4KNn0DjgmPAeBJ
8MJ2VjLQPm/L7LWVz3TsKpEwW9nnKrFc+TBk+zcXXtyLNllan6Z/rWRrJkjOOJwe
+/s8ovW+EYqUz+jvoXQUnI2B4tW923AGwutGcyG/qCgVphqtAAeqJg3E4ah/1wo7
UYCSi8d9TJhIHX3tLomoBjOf9qa5oSzPuZLWxVVPFEt1yfBBzszlPFyPB2x5IUEQ
3ssxKWcmF/BtiCdl+pfWFxAZ23C3qX9NT9CU+rBA/SnhK6U7rdAGoA0EmeREfJn9
gZ9DPSP72dwbzuhIL+DxfON4fodjce15zIiC4YDp42Fon3sX49YWY5E1oGMri78u
S9RoZQR0GZFPcT9tmDur+tdwZiExmcihlfJw6nOBcMs0WAEZe6JGScNsj2q8hs2g
8Iy4QUtq7tBdgOd4ZdD4ELdBgi77ke8CR3Sz9GFx5oUyHw9gvcD7EpNcbw4kv+cg
b6TjLjw83/zRVASJj/9JCqqwg++qbui9zjDH88SJpH0SUTEGmloH8OeMKxaOEEFG
neo4bleAAIZrCQCJ68VnH0eU60MSvWbEcoIzmbEEN3T5VlAReJY=
=ZzFI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6697-1
March 18, 2024

bash vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Bash could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- bash: GNU Bourne Again SHell

Details:

It was discovered that Bash incorrectly handled certain memory operations
when processing commands. If a user or automated system were tricked into
running a specially crafted bash file, a remote attacker could use this
issue to cause Bash to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
bash 5.1-6ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6697-1
CVE-2022-3715

Package Information:
https://launchpad.net/ubuntu/+source/bash/5.1-6ubuntu1.1

No comments:

Post a Comment