Bug 19387 - bash new security issue CVE-2016-0634
Summary: bash new security issue CVE-2016-0634
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal minor
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/701923/
Whiteboard:
Keywords:
Depends on: 19462
Blocks:
  Show dependency treegraph
 
Reported: 2016-09-16 19:46 CEST by David Walser
Modified: 2016-11-21 23:56 CET (History)
4 users (show)

See Also:
Source RPM: bash-4.3-33.1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-09-16 19:46:13 CEST
A minor security issue in bash has been announced today (September 16):
http://www.openwall.com/lists/oss-security/2016/09/16/8

I have added the patches listed in that message in bash in Cauldron.
Comment 1 David Walser 2016-09-17 00:11:16 CEST
There were already some questions as to whether a privilege boundary is really crossed in such a way that an attacker can make use of this issue without having sufficient access to cause much larger problems, and the upstream Bash maintainer's response to the above message indicates the same opinion, so this might not be a *real* security issue.

Perhaps we can update the Mageia 5 package to patchlevel 46 (from 33) to bring it in line with the bugfixes in the Cauldron package, and include the fixes for this, and issue it as a bug fix update.

Severity: normal => minor

Marja Van Waes 2016-09-20 20:10:08 CEST

CC: (none) => marja11
Assignee: bugsquad => shlomif

Comment 2 David Walser 2016-09-23 23:08:56 CEST
Fedora has issued an advisory for this today (September 23):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/5GRFMCTX4O7RTLZX5CI45KC7GGM6XIIY/
David Walser 2016-09-26 20:51:38 CEST

URL: (none) => http://lwn.net/Vulnerabilities/701923/

Comment 3 Thomas Backlund 2016-09-27 20:46:49 CEST
*** Bug 18734 has been marked as a duplicate of this bug. ***

CC: (none) => listas.apl

Comment 4 Thomas Backlund 2016-09-27 20:48:35 CEST
(In reply to Thomas Backlund from comment #3)
> *** Bug 18734 has been marked as a duplicate of this bug. ***

wrong bug dup, sorry

CC: (none) => tmb

Comment 5 David Walser 2016-10-04 14:00:27 CEST
Patches were added to the package but not actually applied (whoops).  Replaced them with Fedora's more complete patch and actually applied it this time.
David Walser 2016-10-04 14:01:25 CEST

Blocks: (none) => 19462

Comment 6 David Walser 2016-10-07 17:50:03 CEST
bash 4.3 patchlevel 47 now includes the fix for this too:
http://openwall.com/lists/oss-security/2016/10/07/6
Comment 7 Nicolas Lécureuil 2016-11-18 01:26:10 CET
available on updates_testing  bash-4.3-48.2.mga5

CC: (none) => mageia
Assignee: shlomif => qa-bugs

Comment 8 David Walser 2016-11-18 01:36:04 CET
Thanks.  We can't assign two bugs to QA for the same package/update, so we'll use the newer bug for that.

Assignee: qa-bugs => mageia

Comment 9 David Walser 2016-11-21 23:56:36 CET
Fixed:
http://advisories.mageia.org/MGASA-2016-0393.html

Status: NEW => RESOLVED
Blocks: 19462 => (none)
Depends on: (none) => 19462
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.