Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1017897

Bug#964986: buster-pu: package ksh/93u+20120801-3.4

From Anuradha Weeraman <anuradha@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#964986: buster-pu: package ksh/93u+20120801-3.4
Date 2020-07-14 01:10 +0200
Message-ID <AsfK9-5Y7-1@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: buster
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org

[ Reason ]
Summary of the issue: In ksh version 20120801, a flaw was found in the
way it evaluates certain environment variables. An attacker could use
this flaw to override or bypass environment restrictions to execute
shell commands.

[ Impact ]
Services and applications that allow remote unauthenticated
attackers to provide one of those environment variables could allow them
to exploit this issue remotely, although the risk is deemed low.

[ Tests ]
There is a test included in the diff that was used to validate the
fix. Also, the regression test suite was run to make sure there were
no regressions.

[ Risks ]
The regression test suite has been run before and after the patch to
confirm no new regressions. Also, the fix is applied in unstable with no
new issues reported.

[ Checklist ]
[X] *all* changes are documented in the d/changelog
[X] I reviewed all changes and I approve them
[X] attach debdiff against the package in (old)stable
[X] the issue is verified as fixed in unstable

[ Changes ]
* Patch to arith.c that fixes the CVE
* Test case for the fix

[ Other info ]
This was brought up to the security team first, and it was deemed that a
DSA is not required by Salvatore Bonaccorso.

Anuradha

-- System Information:
Debian Release: bullseye/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-14 01:10 +0200
  Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Salvatore Bonaccorso <carnil@debian.org> - 2020-07-14 06:30 +0200
    Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-15 00:10 +0200
      Bug#964986: buster-pu: package ksh/93u+20120801-3.4 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-07-25 18:10 +0200
        Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-25 23:10 +0200
  Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2020-07-26 13:20 +0200

csiph-web