Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.870392
Kategorie:Red Hat Local Security Checks
Titel:RedHat Update for bash RHSA-2011:0261-01
Zusammenfassung:The remote host is missing an update for the 'bash'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'bash'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Bash (Bourne-again shell) is the default shell for Red Hat Enterprise
Linux.

It was found that certain scripts bundled with the Bash documentation
created temporary files in an insecure way. A malicious, local user could
use this flaw to conduct a symbolic link attack, allowing them to overwrite
the contents of arbitrary files accessible to the victim running the
scripts. (CVE-2008-5374)

This update also fixes the following bugs:

* If a child process's PID was the same as the PID of a previously ended
child process, Bash did not wait for that child process. In some cases this
caused 'Resource temporarily unavailable' errors. With this update, Bash
recycles PIDs and waits for processes with recycled PIDs. (BZ#521134)

* Bash's built-in 'read' command had a memory leak when 'read' failed due
to no input (pipe for stdin). With this update, the memory is correctly
freed. (BZ#537029)

* Bash did not correctly check for a valid multi-byte string when setting
the IFS value, causing Bash to crash. With this update, Bash checks the
multi-byte string and no longer crashes. (BZ#539536)

* Bash incorrectly set locale settings when using the built-in 'export'
command and setting the locale on the same line (for example, with
'LC_ALL=C export LC_ALL'). With this update, Bash correctly sets locale
settings. (BZ#539538)

All bash users should upgrade to these updated packages, which contain
backported patches to correct these issues.

Affected Software/OS:
bash on Red Hat Enterprise Linux AS version 4,
Red Hat Enterprise Linux ES version 4,
Red Hat Enterprise Linux WS version 4

Solution:
Please Install the Updated Packages.

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2008-5374
BugTraq ID: 32733
http://www.securityfocus.com/bid/32733
http://security.gentoo.org/glsa/glsa-201210-05.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2010:004
http://uvw.ru/report.sid.txt
http://lists.debian.org/debian-devel/2008/08/msg00347.html
http://www.redhat.com/support/errata/RHSA-2011-0261.html
http://www.redhat.com/support/errata/RHSA-2011-1073.html
http://secunia.com/advisories/43365
http://secunia.com/advisories/51086
http://www.vupen.com/english/advisories/2011/0414
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.