You are here
Home > Preporuke > Sigurnosni propusti programskog paketa bash

Sigurnosni propusti programskog paketa bash

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2364-1
September 27, 2014

bash vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS
– Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in Bash.

Software Description:
– bash: GNU Bourne Again SHell

Details:

Florian Weimer and Todd Sabin discovered that the Bash parser incorrectly
handled memory. An attacker could possibly use this issue to bypass certain
environment restrictions and execute arbitrary code. (CVE-2014-7186,
CVE-2014-7187)

In addition, this update introduces a hardening measure which adds prefixes
and suffixes around environment variable names which contain shell
functions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
bash 4.3-7ubuntu1.4

Ubuntu 12.04 LTS:
bash 4.2-2ubuntu2.5

Ubuntu 10.04 LTS:
bash 4.1-2ubuntu3.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2364-1
CVE-2014-7186, CVE-2014-7187

Package Information:
https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.4
https://launchpad.net/ubuntu/+source/bash/4.2-2ubuntu2.5
https://launchpad.net/ubuntu/+source/bash/4.1-2ubuntu3.4

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJUJn/NAAoJEGVp2FWnRL6TeZIP/3L+cWuZ3KEKNkxPSiEr3C/+
iQffK/QfnVW7OtQodOqvKWhy2ftSWOEkwDnuN+Kw3kIinpepqfAr9m7PstXp3/UW
2WQLvrMUk+3i2vwtLmwuDq9pKQZr1/HRh04RDMsf6r1aspoN4VprA0UWyl9ZvhPc
Afew1NMfSWAwOhpeQPuXzh3962iq7Is2KsQMVRWfr8euqZqfgoeU93rdExHtZVDy
qZEfCjoUzDHinfKbzEt8TwSIULNPOY1bzDK7GrVHIYVDeLUeuRrp/6+wNudHBwic
vyGnOZEdoabLoB9kwJcL5i652B/L5Fcd5uQNRlfZKU6aapTLCoGwiG5Nz7iIAbcu
Z9xtqj7FkvsIAqm7j8VWibxw5NE3RFURktonHfNfh8XZ9dPwGi7J67UEOLN0xkae
8/bE9e7ePhPV4L/XSnVU2oQsKTDk2mAggBopB3ePoFibTJ8zVSb4g74KUpemRU0S
qRVAEuTwN1B12mDCeU2UcqpuIgeAC6IIrEnM+J6CKyoijvylIwYre5NhF3zlcgA9
FHkAP8MibEEWXaytRlPfArGiKw9NPQBGEM4LiYGin7r7bGakpIwYlzPXH8k1f0qv
tKeDKI+dvI74v83W4JOrANaoDn1tkeVGTmL3QEuecCLK9itLpZfv+HFxOnZEO9QR
j/AJU8vvfm2HF+FwC6um
=6T2i
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2014-09-0037-ADV
CveCVE-2014-7186 CVE-2014-7187
ID izvornikaUSN-2364-1
Proizvodbash
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Kritična ranjivost programskog paketa bash

Otkrivena je kritična ranjivost u načinu kojim je Bash obrađivao posebno oblikovane varijable okruženja. Potencijalni udaljeni napadači mogu iskoristiti ranjivost...

Close