]> code.ossystems Code Review - openembedded-core.git/commit
bash: Fix for CVE-2014-7186 and CVE-2014-7187
authorCatalin Popeanga <Catalin.Popeanga@enea.com>
Thu, 9 Oct 2014 12:24:29 +0000 (14:24 +0200)
committerPaul Eggleton <paul.eggleton@linux.intel.com>
Sun, 12 Oct 2014 20:24:36 +0000 (21:24 +0100)
commitbdfe1e3770aeee9a1a7c65d4834f1a99820d3140
tree54370e45086ad8b78c8ddaa1650e1da7f5bd6ddb
parentaf1f65b57dbfcaf5fc7c254dce80ac55f3a632cb
bash: Fix for CVE-2014-7186 and CVE-2014-7187

This is a followup patch to incomplete CVE-2014-6271 fix code execution via
specially-crafted environment

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187

(From OE-Core daisy rev: 153d1125659df9e5c09e35a58bd51be184cb13c1)

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
meta/recipes-extended/bash/bash-3.2.48/cve-2014-7186_cve-2014-7187.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash-4.2/cve-2014-7186_cve-2014-7187.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash_3.2.48.bb
meta/recipes-extended/bash/bash_4.2.bb