DSA-3032-1 bash -- security update

Related Vulnerabilities: CVE-2014-6271  

Stephane Chazelas discovered a vulnerability in bash, the GNU Bourne-Again Shell, related to how environment variables are processed. In many common configurations, this vulnerability is exploitable over the network, especially if bash has been configured as the system shell. For the stable distribution (wheezy), this problem has been fixed in version 4.2+dfsg-0.1+deb7u1. We recommend that you upgrade your bash packages.

Debian Security Advisory

DSA-3032-1 bash -- security update

Date Reported:
24 Sep 2014
Affected Packages:
bash
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-6271.
More information:

Stephane Chazelas discovered a vulnerability in bash, the GNU Bourne-Again Shell, related to how environment variables are processed. In many common configurations, this vulnerability is exploitable over the network, especially if bash has been configured as the system shell.

For the stable distribution (wheezy), this problem has been fixed in version 4.2+dfsg-0.1+deb7u1.

We recommend that you upgrade your bash packages.