Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1017897 > unrolled thread

Bug#964986: buster-pu: package ksh/93u+20120801-3.4

Started byAnuradha Weeraman <anuradha@debian.org>
First post2020-07-14 01:10 +0200
Last post2020-07-26 13:20 +0200
Articles 6 — 4 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-14 01:10 +0200
    Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Salvatore Bonaccorso <carnil@debian.org> - 2020-07-14 06:30 +0200
      Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-15 00:10 +0200
        Bug#964986: buster-pu: package ksh/93u+20120801-3.4 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-07-25 18:10 +0200
          Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-25 23:10 +0200
    Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2020-07-26 13:20 +0200

#1017897 — Bug#964986: buster-pu: package ksh/93u+20120801-3.4

FromAnuradha Weeraman <anuradha@debian.org>
Date2020-07-14 01:10 +0200
SubjectBug#964986: buster-pu: package ksh/93u+20120801-3.4
Message-ID<AsfK9-5Y7-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
Tags: buster
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org

[ Reason ]
Summary of the issue: In ksh version 20120801, a flaw was found in the
way it evaluates certain environment variables. An attacker could use
this flaw to override or bypass environment restrictions to execute
shell commands.

[ Impact ]
Services and applications that allow remote unauthenticated
attackers to provide one of those environment variables could allow them
to exploit this issue remotely, although the risk is deemed low.

[ Tests ]
There is a test included in the diff that was used to validate the
fix. Also, the regression test suite was run to make sure there were
no regressions.

[ Risks ]
The regression test suite has been run before and after the patch to
confirm no new regressions. Also, the fix is applied in unstable with no
new issues reported.

[ Checklist ]
[X] *all* changes are documented in the d/changelog
[X] I reviewed all changes and I approve them
[X] attach debdiff against the package in (old)stable
[X] the issue is verified as fixed in unstable

[ Changes ]
* Patch to arith.c that fixes the CVE
* Test case for the fix

[ Other info ]
This was brought up to the security team first, and it was deemed that a
DSA is not required by Salvatore Bonaccorso.

Anuradha

-- System Information:
Debian Release: bullseye/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

[toc] | [next] | [standalone]


#1017914

FromSalvatore Bonaccorso <carnil@debian.org>
Date2020-07-14 06:30 +0200
Message-ID<AskJP-xe-3@gated-at.bofh.it>
In reply to#1017897
Hi Anuradha,

[disclaimer: not a member of the release team, so not an authoritative
reply]

On Mon, Jul 13, 2020 at 06:56:27PM -0400, Anuradha Weeraman wrote:
> Package: release.debian.org
> Severity: normal
> Tags: buster
> User: release.debian.org@packages.debian.org
> Usertags: pu
> X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org
> 
> [ Reason ]
> Summary of the issue: In ksh version 20120801, a flaw was found in the
> way it evaluates certain environment variables. An attacker could use
> this flaw to override or bypass environment restrictions to execute
> shell commands.
> 
> [ Impact ]
> Services and applications that allow remote unauthenticated
> attackers to provide one of those environment variables could allow them
> to exploit this issue remotely, although the risk is deemed low.
> 
> [ Tests ]
> There is a test included in the diff that was used to validate the
> fix. Also, the regression test suite was run to make sure there were
> no regressions.
> 
> [ Risks ]
> The regression test suite has been run before and after the patch to
> confirm no new regressions. Also, the fix is applied in unstable with no
> new issues reported.
> 
> [ Checklist ]
> [X] *all* changes are documented in the d/changelog
> [X] I reviewed all changes and I approve them
> [X] attach debdiff against the package in (old)stable
> [X] the issue is verified as fixed in unstable
> 
> [ Changes ]
> * Patch to arith.c that fixes the CVE
> * Test case for the fix
> 
> [ Other info ]
> This was brought up to the security team first, and it was deemed that a
> DSA is not required by Salvatore Bonaccorso.

Small change is needed in the debdiff:

> diff -Nru ksh-93u+20120801/debian/changelog ksh-93u+20120801/debian/changelog
> --- ksh-93u+20120801/debian/changelog	2018-12-14 02:26:58.000000000 -0500
> +++ ksh-93u+20120801/debian/changelog	2020-07-12 11:26:07.000000000 -0400
> @@ -1,3 +1,15 @@
> +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high
 
The target distribution would need to be 'buster' in this case of the
upload for the point release.

Thanks for your work on this update,

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#1018011

FromAnuradha Weeraman <anuradha@debian.org>
Date2020-07-15 00:10 +0200
Message-ID<AsBhE-25v-3@gated-at.bofh.it>
In reply to#1017914
On Tue, Jul 14, 2020 at 06:16:30AM +0200, Salvatore Bonaccorso wrote:
> Small change is needed in the debdiff:
> 
> > diff -Nru ksh-93u+20120801/debian/changelog ksh-93u+20120801/debian/changelog
> > --- ksh-93u+20120801/debian/changelog	2018-12-14 02:26:58.000000000 -0500
> > +++ ksh-93u+20120801/debian/changelog	2020-07-12 11:26:07.000000000 -0400
> > @@ -1,3 +1,15 @@
> > +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high
>  
> The target distribution would need to be 'buster' in this case of the
> upload for the point release.

Noted, thanks, will consider along with any input from the release team.

Anuradha

[toc] | [prev] | [next] | [standalone]


#1019256

From"Adam D. Barratt" <adam@adam-barratt.org.uk>
Date2020-07-25 18:10 +0200
Message-ID<AwuUh-69B-5@gated-at.bofh.it>
In reply to#1018011
Control: tags -1 + confirmed

On Tue, 2020-07-14 at 17:59 -0400, Anuradha Weeraman wrote:
> On Tue, Jul 14, 2020 at 06:16:30AM +0200, Salvatore Bonaccorso wrote:
> > Small change is needed in the debdiff:
> > 
> > > diff -Nru ksh-93u+20120801/debian/changelog ksh-
> > > 93u+20120801/debian/changelog
> > > --- ksh-93u+20120801/debian/changelog	2018-12-14
> > > 02:26:58.000000000 -0500
> > > +++ ksh-93u+20120801/debian/changelog	2020-07-12
> > > 11:26:07.000000000 -0400
> > > @@ -1,3 +1,15 @@
> > > +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high
> >  
> > The target distribution would need to be 'buster' in this case of
> > the upload for the point release.
> 
> Noted, thanks, will consider along with any input from the release
> team.

One other small change - the version should be "93u+20120801-
3.4+deb10u1", as the current Debian revision is 3.4, not 4.

With those updated, please go ahead.

Regards,

Adam

[toc] | [prev] | [next] | [standalone]


#1019287

FromAnuradha Weeraman <anuradha@debian.org>
Date2020-07-25 23:10 +0200
Message-ID<AwzAB-vU-9@gated-at.bofh.it>
In reply to#1019256
On Sat, Jul 25, 2020 at 05:00:21PM +0100, Adam D. Barratt wrote:
> > > The target distribution would need to be 'buster' in this case of
> > > the upload for the point release.
> > 
> > Noted, thanks, will consider along with any input from the release
> > team.
> 
> One other small change - the version should be "93u+20120801-
> 3.4+deb10u1", as the current Debian revision is 3.4, not 4.
> 
> With those updated, please go ahead.

Thanks. I have uploaded with the suggested changes:

distribution=buster
version=93u+20120801-3.4+deb10u1

Anuradha

[toc] | [prev] | [next] | [standalone]


#1019339 — Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance

FromAdam D Barratt <adam@adam-barratt.org.uk>
Date2020-07-26 13:20 +0200
SubjectBug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance
Message-ID<AwMRb-7g-5@gated-at.bofh.it>
In reply to#1017897
package release.debian.org
tags 964986 = buster pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian buster.

Thanks for your contribution!

Upload details
==============

Package: ksh
Version: 93u+20120801-3.4+deb10u1

Explanation: fix environment variable restriction issue [CVE-2019-14868]

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web