{"id":"MGASA-2014-0388","summary":"Updated bash packages fix CVE-2014-6271","details":"Updated bash packages fix security vulnerability:\n\nA flaw was found in the way Bash evaluated certain specially crafted\nenvironment variables. An attacker could use this flaw to override or\nbypass environment restrictions to execute shell commands. Certain\nservices and applications allow remote unauthenticated attackers to\nprovide environment variables, allowing them to exploit this issue\n(CVE-2014-6271).\n\nBash has been updated version 4.2 patch level 37 to patch level 48 to fix\nthis issue, as well as several other bugs.  See the upstream patches for\ndetails on the other bugs.\n\nThis vulnerability can be exposed and exploited through several other\npieces of software and should be considered highly critical.  Please refer\nto the RedHat Knowledge Base article and blog post for more information.\n\nAll users and sysadmins are advised to update their bash package immediately.\n","modified":"2026-04-16T01:49:13.645360857Z","published":"2014-09-24T18:42:05Z","upstream":["CVE-2014-6271"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0388.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14167"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-1293.html"},{"type":"WEB","url":"https://access.redhat.com/articles/1200223"},{"type":"WEB","url":"https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/"},{"type":"WEB","url":"ftp://ftp.cwru.edu/pub/bash/bash-4.2-patches/"}],"affected":[{"package":{"name":"bash","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/bash?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2-48.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0388.json"}},{"package":{"name":"bash","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/bash?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2-48.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0388.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}