USN-3294-1: Bash vulnerabilities
USN-3294-1: Bash vulnerabilities Ubuntu Security Notice USN-3294-1 17th May, 2017 bash vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Bash. Software description bash – GNU Bourne Again SHell Details Bernd Dietzel discovered that Bash incorrectly expanded the hostname whendisplaying the prompt. If a remote attacker were able to modify a hostname,this flaw could be exploited to execute arbitrary code. This issue onlyaffected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.(CVE-2016-0634) It was discovered that Bash incorrectly handled the SHELLOPTS and PS4environment variables. A local attacker could use this issue to executearbitrary code with root privileges. This issue only affected Ubuntu 14.04LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543) It was discovered that Bash incorrectly handled the popd command. [ more… ]