Skip to content
This repository has been archived by the owner on Jan 31, 2020. It is now read-only.

bash: security update to patch level 7 #49

Closed
MingcongBai opened this issue Feb 8, 2017 · 0 comments
Closed

bash: security update to patch level 7 #49

MingcongBai opened this issue Feb 8, 2017 · 0 comments
Labels
Milestone

Comments

@MingcongBai
Copy link
Contributor

An exploit can be realized by creating a file or directory with a specially crafted name. A user utilizing GNU Bash’s built-in path completion by hitting the Tab button (f.e. to remove it with rm) triggers the exploit without executing a command itself. The vulnerability has been introduced on the devel -branch in May 2015.

CVE-2017-5932 was just assigned for this particular vulnerability, which is fixed with patch level 7.

Bash for AOSC OS Core has been updated to patch level 12, which includes a fix for this particular security vulnerability - with commit f6105ba. Use AOSA-2017-0019 for this issue.

@MingcongBai MingcongBai added this to the Core 4.2 milestone Feb 8, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant