A flaw was found in the bash functionality that evaluates specially formatted environment variables passed to it from another environment. An attacker could use this feature to override or bypass restrictions to the environment to execute shell commands before restrictions have been applied. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.
Acknowledgements:
Red Hat would like to thank Stephane Chazelas for reporting this issue.
End of life: 3/31/2028, Latest version: 10
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and modcgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Bodo Möller, Thai Duong and Krzysztof Kotowicz of Google discovered a flaw in the design of SSL version 3.0 that would allow an attacker to calculate the plaintext of secure connections, allowing, for example, secure HTTP cookies to be stolen.
References: http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html https://www.openssl.org/~bodo/ssl-poodle.pdf
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcpconnect.c, (2) server/eventscript.c, (3) tools/ctdbdiagnostics, (4) config/gdbbacktrace, and (5) include/ctdbprivate.h.
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
End of life: 9/29/2026, Latest version: 9
End of life: 9/29/2026, Latest version: 9
End of life: 11/30/2023, Latest version: 8
End of life: 11/30/2023, Latest version: 8
End of life: 6/30/2021, Latest version: 7
End of life: 6/30/2021, Latest version: 7
End of life: 9/30/2019, Latest version: 6
End of life: 9/30/2019, Latest version: 6
End of life: 12/31/2017, Latest version: 5
End of life: 12/31/2017, Latest version: 5
End of life: 9/19/2015, Latest version: 4
End of life: 9/19/2015, Latest version: 4
End of life: 11/26/2014, Latest version: 3
End of life: 11/26/2014, Latest version: 3
End of life: 11/22/2013, Latest version: 2
End of life: 11/22/2013, Latest version: 2
End of life: 12/1/2012, Latest version: 1
End of life: 12/1/2012, Latest version: 1