REDHAT-BUG-1377613: Medium severity gnu bash vulnerability
A vulnerability was found in a way bash expands the $HOSTNAME. Injecting the hostname with malicious code would cause it to run each time bash expanded \h in the prompt string.
References:
http://seclists.org/oss-sec/2016/q3/528
Ubuntu bug:
https://bugs.launchpad.net/ubuntu/+source/bash/+bug/1507025
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1377613?
The vulnerability REDHAT-BUG-1377613 is considered to be of medium severity as it allows the execution of arbitrary code through a compromised hostname.
How do I fix REDHAT-BUG-1377613?
To fix REDHAT-BUG-1377613, update your GNU Bash to the latest patched version provided by your distribution.
What are the potential risks of REDHAT-BUG-1377613?
The potential risks of REDHAT-BUG-1377613 include unauthorized code execution and possible system compromises if an attacker is able to manipulate the hostname.
Which versions of Bash are affected by REDHAT-BUG-1377613?
REDHAT-BUG-1377613 affects particular versions of GNU Bash but specific version numbers should be checked in the security advisories for your distribution.
How can I identify if REDHAT-BUG-1377613 is present in my system?
To identify if REDHAT-BUG-1377613 is present in your system, review your Bash configuration for any unusual hostname settings or conduct a security scan.