Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1017914

Bug#964986: buster-pu: package ksh/93u+20120801-3.4

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#964986: buster-pu: package ksh/93u+20120801-3.4
Date 2020-07-14 06:30 +0200
Message-ID <AskJP-xe-3@gated-at.bofh.it> (permalink)
References <AsfK9-5Y7-1@gated-at.bofh.it> <AsfK9-5Y7-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Hi Anuradha,

[disclaimer: not a member of the release team, so not an authoritative
reply]

On Mon, Jul 13, 2020 at 06:56:27PM -0400, Anuradha Weeraman wrote:
> Package: release.debian.org
> Severity: normal
> Tags: buster
> User: release.debian.org@packages.debian.org
> Usertags: pu
> X-Debbugs-Cc: anuradha@debian.org, carnil@debian.org
> 
> [ Reason ]
> Summary of the issue: In ksh version 20120801, a flaw was found in the
> way it evaluates certain environment variables. An attacker could use
> this flaw to override or bypass environment restrictions to execute
> shell commands.
> 
> [ Impact ]
> Services and applications that allow remote unauthenticated
> attackers to provide one of those environment variables could allow them
> to exploit this issue remotely, although the risk is deemed low.
> 
> [ Tests ]
> There is a test included in the diff that was used to validate the
> fix. Also, the regression test suite was run to make sure there were
> no regressions.
> 
> [ Risks ]
> The regression test suite has been run before and after the patch to
> confirm no new regressions. Also, the fix is applied in unstable with no
> new issues reported.
> 
> [ Checklist ]
> [X] *all* changes are documented in the d/changelog
> [X] I reviewed all changes and I approve them
> [X] attach debdiff against the package in (old)stable
> [X] the issue is verified as fixed in unstable
> 
> [ Changes ]
> * Patch to arith.c that fixes the CVE
> * Test case for the fix
> 
> [ Other info ]
> This was brought up to the security team first, and it was deemed that a
> DSA is not required by Salvatore Bonaccorso.

Small change is needed in the debdiff:

> diff -Nru ksh-93u+20120801/debian/changelog ksh-93u+20120801/debian/changelog
> --- ksh-93u+20120801/debian/changelog	2018-12-14 02:26:58.000000000 -0500
> +++ ksh-93u+20120801/debian/changelog	2020-07-12 11:26:07.000000000 -0400
> @@ -1,3 +1,15 @@
> +ksh (93u+20120801-4+deb10u1) buster-security; urgency=high
 
The target distribution would need to be 'buster' in this case of the
upload for the point release.

Thanks for your work on this update,

Regards,
Salvatore

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-14 01:10 +0200
  Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Salvatore Bonaccorso <carnil@debian.org> - 2020-07-14 06:30 +0200
    Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-15 00:10 +0200
      Bug#964986: buster-pu: package ksh/93u+20120801-3.4 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-07-25 18:10 +0200
        Bug#964986: buster-pu: package ksh/93u+20120801-3.4 Anuradha Weeraman <anuradha@debian.org> - 2020-07-25 23:10 +0200
  Bug#964986: ksh 93u+20120801-3.4+deb10u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2020-07-26 13:20 +0200

csiph-web