USN-2363-2: Bash vulnerability
26 September 2014
Bash allowed bypassing environment restrictions in certain environments.
- bash - GNU Bourne Again SHell
USN-2363-1 fixed a vulnerability in Bash. Due to a build issue, the patch
for CVE-2014-7169 didn't get properly applied in the Ubuntu 14.04 LTS
package. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Tavis Ormandy discovered that the security fix for Bash included in
USN-2362-1 was incomplete. An attacker could use this issue to bypass
certain environment restrictions. (CVE-2014-7169)
- USN-2363-1: bash-static, bash-doc, bash, bash-builtins