SuSE: 2014:1214-1: critical: bash
Summary
bash has been updated to fix a critical security issue.
In some circumstances, the shell would evaluate shellcode in environment
variables passed at startup time. This allowed code execution by local or
remote attackers who could pass environment variables to bash scripts.
(CVE-2014-6271)
Additionally, the following bugs have been fixed:
* Avoid possible buffer overflow when expanding the /dev/fd prefix
with e.g. the test built-in. (CVE-2012-3410)
* Enable workaround for changed behavior of sshd. (bnc#688469)
Security Issues:
* CVE-2014-6271
References
#688469 #770795 #896776
Cross- CVE-2012-3410 CVE-2014-0475
Affected Products:
SUSE Linux Enterprise Server 10 SP3 LTSS
https://www.suse.com/security/cve/CVE-2012-3410.html
https://www.suse.com/security/cve/CVE-2014-0475.html
https://bugzilla.suse.com/688469
https://bugzilla.suse.com/770795
https://bugzilla.suse.com/896776
https://scc.suse.com:443/patches/