SuSE 11.3 Security Update : bash (SAT Patch Number 9780)

critical Nessus Plugin ID 77958

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

The command-line shell 'bash' evaluates environment variables, which allows the injection of characters and might be used to access files on the system in some circumstances. (CVE-2014-7169)

Please note that this issue is different from a previously fixed vulnerability tracked under CVE-2014-6271 and is less serious due to the special, non-default system configuration that is needed to create an exploitable situation.

To remove further exploitation potential we now limit the function-in-environment variable to variables prefixed with BASH_FUNC_. This hardening feature is work in progress and might be improved in later updates.

Additionally, two other security issues have been fixed :

- Nested HERE documents could lead to a crash of bash.
(CVE-2014-7186)

- Nesting of for loops could lead to a crash of bash.
(CVE-2014-7187)

Solution

Apply SAT patch number 9780.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=898346

https://bugzilla.novell.com/show_bug.cgi?id=898603

https://bugzilla.novell.com/show_bug.cgi?id=898604

http://support.novell.com/security/cve/CVE-2014-6271.html

http://support.novell.com/security/cve/CVE-2014-7169.html

http://support.novell.com/security/cve/CVE-2014-7186.html

http://support.novell.com/security/cve/CVE-2014-7187.html

Plugin Details

Severity: Critical

ID: 77958

File Name: suse_11_bash-140926.nasl

Version: 1.14

Type: local

Agent: unix

Published: 9/29/2014

Updated: 12/5/2022

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:libreadline5, p-cpe:/a:novell:suse_linux:11:bash, p-cpe:/a:novell:suse_linux:11:libreadline5-32bit, cpe:/o:novell:suse_linux:11, p-cpe:/a:novell:suse_linux:11:readline-doc, p-cpe:/a:novell:suse_linux:11:bash-doc

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/26/2014

CISA Known Exploited Vulnerability Due Dates: 7/28/2022

Exploitable With

Core Impact

Metasploit (Apache mod_cgi Bash Environment Variable Code Injection (Shellshock))

Reference Information

CVE: CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187

IAVA: 2014-A-0142