Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1017897 > unrolled thread
| Started by | Anuradha Weeraman <anuradha@debian.org> |
|---|---|
| First post | 2020-07-14 01:10 +0200 |
| Last post | 2020-07-26 13:20 +0200 |
| Articles | 6 — 4 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-14 01:10 +0200
Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Salvatore Bonaccorso <carnil@debian.org> - 2020-07-14 06:30 +0200
Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-15 00:10 +0200
Bug#964986: buster-pu: package ksh/93u+20120801-3.4 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-07-25 18:10 +0200
Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-25 23:10 +0200
Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2020-07-26 13:20 +0200
| From | Anuradha Weeraman <anuradha@debian.org> |
|---|---|
| Date | 2020-07-14 01:10 +0200 |
| Subject | Bug#964986: buster-pu: package ksh/93u+20120801-3.4 |
| Message-ID | <AsfK9-5Y7-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Package: release.debian.org Severity: normal Tags: buster User: release.debian.org@packages.debian.org Usertags: pu X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org [ Reason ] Summary of the issue: In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. [ Impact ] Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely, although the risk is deemed low. [ Tests ] There is a test included in the diff that was used to validate the fix. Also, the regression test suite was run to make sure there were no regressions. [ Risks ] The regression test suite has been run before and after the patch to confirm no new regressions. Also, the fix is applied in unstable with no new issues reported. [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] * Patch to arith.c that fixes the CVE * Test case for the fix [ Other info ] This was brought up to the security team first, and it was deemed that a DSA is not required by Salvatore Bonaccorso. Anuradha -- System Information: Debian Release: bullseye/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64)
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2020-07-14 06:30 +0200 |
| Message-ID | <AskJP-xe-3@gated-at.bofh.it> |
| In reply to | #1017897 |
Hi Anuradha, [disclaimer: not a member of the release team, so not an authoritative reply] On Mon, Jul 13, 2020 at 06:56:27PM -0400, Anuradha Weeraman wrote: > Package: release.debian.org > Severity: normal > Tags: buster > User: release.debian.org@packages.debian.org > Usertags: pu > X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org > > [ Reason ] > Summary of the issue: In ksh version 20120801, a flaw was found in the > way it evaluates certain environment variables. An attacker could use > this flaw to override or bypass environment restrictions to execute > shell commands. > > [ Impact ] > Services and applications that allow remote unauthenticated > attackers to provide one of those environment variables could allow them > to exploit this issue remotely, although the risk is deemed low. > > [ Tests ] > There is a test included in the diff that was used to validate the > fix. Also, the regression test suite was run to make sure there were > no regressions. > > [ Risks ] > The regression test suite has been run before and after the patch to > confirm no new regressions. Also, the fix is applied in unstable with no > new issues reported. > > [ Checklist ] > [X] *all* changes are documented in the d/changelog > [X] I reviewed all changes and I approve them > [X] attach debdiff against the package in (old)stable > [X] the issue is verified as fixed in unstable > > [ Changes ] > * Patch to arith.c that fixes the CVE > * Test case for the fix > > [ Other info ] > This was brought up to the security team first, and it was deemed that a > DSA is not required by Salvatore Bonaccorso. Small change is needed in the debdiff: > diff -Nru ksh-93u+20120801/debian/changelog ksh-93u+20120801/debian/changelog > --- ksh-93u+20120801/debian/changelog 2018-12-14 02:26:58.000000000 -0500 > +++ ksh-93u+20120801/debian/changelog 2020-07-12 11:26:07.000000000 -0400 > @@ -1,3 +1,15 @@ > +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high The target distribution would need to be 'buster' in this case of the upload for the point release. Thanks for your work on this update, Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | Anuradha Weeraman <anuradha@debian.org> |
|---|---|
| Date | 2020-07-15 00:10 +0200 |
| Message-ID | <AsBhE-25v-3@gated-at.bofh.it> |
| In reply to | #1017914 |
On Tue, Jul 14, 2020 at 06:16:30AM +0200, Salvatore Bonaccorso wrote: > Small change is needed in the debdiff: > > > diff -Nru ksh-93u+20120801/debian/changelog ksh-93u+20120801/debian/changelog > > --- ksh-93u+20120801/debian/changelog 2018-12-14 02:26:58.000000000 -0500 > > +++ ksh-93u+20120801/debian/changelog 2020-07-12 11:26:07.000000000 -0400 > > @@ -1,3 +1,15 @@ > > +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high > > The target distribution would need to be 'buster' in this case of the > upload for the point release. Noted, thanks, will consider along with any input from the release team. Anuradha
[toc] | [prev] | [next] | [standalone]
| From | "Adam D. Barratt" <adam@adam-barratt.org.uk> |
|---|---|
| Date | 2020-07-25 18:10 +0200 |
| Message-ID | <AwuUh-69B-5@gated-at.bofh.it> |
| In reply to | #1018011 |
Control: tags -1 + confirmed On Tue, 2020-07-14 at 17:59 -0400, Anuradha Weeraman wrote: > On Tue, Jul 14, 2020 at 06:16:30AM +0200, Salvatore Bonaccorso wrote: > > Small change is needed in the debdiff: > > > > > diff -Nru ksh-93u+20120801/debian/changelog ksh- > > > 93u+20120801/debian/changelog > > > --- ksh-93u+20120801/debian/changelog 2018-12-14 > > > 02:26:58.000000000 -0500 > > > +++ ksh-93u+20120801/debian/changelog 2020-07-12 > > > 11:26:07.000000000 -0400 > > > @@ -1,3 +1,15 @@ > > > +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high > > > > The target distribution would need to be 'buster' in this case of > > the upload for the point release. > > Noted, thanks, will consider along with any input from the release > team. One other small change - the version should be "93u+20120801- 3.4+deb10u1", as the current Debian revision is 3.4, not 4. With those updated, please go ahead. Regards, Adam
[toc] | [prev] | [next] | [standalone]
| From | Anuradha Weeraman <anuradha@debian.org> |
|---|---|
| Date | 2020-07-25 23:10 +0200 |
| Message-ID | <AwzAB-vU-9@gated-at.bofh.it> |
| In reply to | #1019256 |
On Sat, Jul 25, 2020 at 05:00:21PM +0100, Adam D. Barratt wrote: > > > The target distribution would need to be 'buster' in this case of > > > the upload for the point release. > > > > Noted, thanks, will consider along with any input from the release > > team. > > One other small change - the version should be "93u+20120801- > 3.4+deb10u1", as the current Debian revision is 3.4, not 4. > > With those updated, please go ahead. Thanks. I have uploaded with the suggested changes: distribution=buster version=93u+20120801-3.4+deb10u1 Anuradha
[toc] | [prev] | [next] | [standalone]
| From | Adam D Barratt <adam@adam-barratt.org.uk> |
|---|---|
| Date | 2020-07-26 13:20 +0200 |
| Subject | Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance |
| Message-ID | <AwMRb-7g-5@gated-at.bofh.it> |
| In reply to | #1017897 |
package release.debian.org tags 964986 = buster pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian buster. Thanks for your contribution! Upload details ============== Package: ksh Version: 93u+20120801-3.4+deb10u1 Explanation: fix environment variable restriction issue [CVE-2019-14868]
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web