CVE-2014-7169

Priority
High
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain
malformed function definitions in the values of environment variables,
which allows remote attackers to write to files or possibly have unknown
other impact via a crafted environment, as demonstrated by vectors
involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and
mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified
DHCP clients, and other situations in which setting the environment occurs
across a privilege boundary from Bash execution. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-6271.
References
Bugs
Notes
 mdeslaur> It was discovered that a build issue preventing the fix
 mdeslaur> from being applied properly in the 4.3-7ubuntu1.2 package for
 mdeslaur> Ubuntu 14.04 LTS. A respin was released to 4.3-7ubuntu1.3 to
 mdeslaur> correct the issue, and USN-2363-2 was published.
Assigned-to
mdeslaur
Package
Source: bash (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 LTS (Precise Pangolin):released (4.2-2ubuntu2.3)
Ubuntu 14.04 LTS (Trusty Tahr):released (4.3-7ubuntu1.3)
Patches:
Proposed:http://www.openwall.com/lists/oss-security/2014/09/25/10
More Information

Updated: 2016-03-23 03:41:31 UTC (commit 10817)