CVE-2014-7169

Priority
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain
malformed function definitions in the values of environment variables,
which allows remote attackers to write to files or possibly have unknown
other impact via a crafted environment, as demonstrated by vectors
involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and
mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified
DHCP clients, and other situations in which setting the environment occurs
across a privilege boundary from Bash execution. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2014-6271.
Assigned-to
mdeslaur
Notes
mdeslaurIt was discovered that a build issue preventing the fix
from being applied properly in the 4.3-7ubuntu1.2 package for
Ubuntu 14.04 LTS. A respin was released to 4.3-7ubuntu1.3 to
correct the issue, and USN-2363-2 was published.
Package
Source: bash (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 14.04 ESM (Trusty Tahr):released (4.3-7ubuntu1.3)
Patches:
Proposed:http://www.openwall.com/lists/oss-security/2014/09/25/10
More Information

Updated: 2020-03-18 22:28:02 UTC (commit 2ea7df7bd1e69e1e489978d2724a936eb3faa1b8)