MGASA-2021-0288
Dashboard / Vulnerabilities / MGASA-2021-0288
Summary: Updated bash packages fix a security vulnerability
Details: A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id. Bash may be vulnerable to this flaw if the setuid permission is set and the owner of the bash program itself is a non-root user. A local attacker could exploit this flaw to escalate their privileges on the system (CVE-2019-18276).
References: https://advisories.mageia.org/MGASA-2021-0288.html, https://bugs.mageia.org/show_bug.cgi?id=28937, https://access.redhat.com/errata/RHSA-2021:1679
Affected packages
Package
Name: bash
Purl: pkg:rpm/mageia/bash?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -4.4-23.1.2.mga7
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
