Git-Url: http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=f78cd14c844b5ec3b38e92c1c49a0dff05e09c60
commit f78cd14c844b5ec3b38e92c1c49a0dff05e09c60 Author: kikadf <[email protected]> Date: Sun Oct 12 17:58:59 2014 +0200 Add FSA for bash diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml index 6e4169e..49f2e24 100644 --- a/frugalware/xml/security.xml +++ b/frugalware/xml/security.xml @@ -38,6 +38,19 @@ --> <fsas> + fsa> + <id>921</id> + <date>2014-10-12</date> + <author>kikadf</author> + <package>bash</package> + <vulnerable>4.2_045-5arcturus2</vulnerable> + <unaffected>4.2_053-1arcturus1</unaffected> + <bts></bts> + <cve>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6277 + http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6278</cve> + <desc>Michal Zalewski discovered that Bash incorrectly handled parsing certain function definitions. If an attacker were able to create an environment variable containing a function definition with a very specific name, these + issues could possibly be used to bypass certain environment restrictions and execute arbitrary code.</desc> + </fsa> <fsa> <id>920</id> <date>2014-10-12</date> _______________________________________________ Frugalware-git mailing list [email protected] http://frugalware.org/mailman/listinfo/frugalware-git
