Mantis - bash
Viewing Issue Advanced Details
5208 regular use block have not tried 2014-09-25 09:46 2014-09-28 00:29
laurent  
yann  
normal  
closed  
fixed  
none    
none  
0005208: Major vulnerabilities in bash
It's been reported that the recently announced vulnerabilities in bash are impacting OpenCSW's.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271 [^]

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169 [^]
I've not checked myself yet, hence the tag above, but I don't doubt it's true. I'm in the process of assessing its impact on business, an OpenCSW package upgrade surely would help.
Issue History
2014-09-25 09:46 laurent New Issue
2014-09-25 10:40 laurent Note Added: 0010922
2014-09-25 20:16 upengan Issue Monitored: upengan
2014-09-28 00:11 yann Note Added: 0010926
2014-09-28 00:11 yann Assigned To => yann
2014-09-28 00:11 yann Status new => resolved
2014-09-28 00:29 yann Status resolved => closed
2014-09-28 00:29 yann Resolution open => fixed

Notes
(0010922)
laurent   
2014-09-25 10:40   
From the m/l:

Hi,

Yes, it is vulnerable.
But bash-4.3.25,REV=2014.09.25 mitigates this security issue, you will find this package in my experimental repository http://buildfarm.opencsw.org/opencsw/experimental/yann [^] and it will soon land in unstable and testing repositories.

However the story is not finished as the current fix doesn't yet solve all the problems, another CVE has been issued to track the remaining ones: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169 [^]

Expect another update when the new security fix is out.

Yann
(0010926)
yann   
2014-09-28 00:11   
Last package bash 4.3.25,REV=2014.09.26 contains the security fix for CVE 2014 7169

I am closing this bug.

Yann