SB2017011343 - Use-after-free in bash (Alpine package)
Published: January 13, 2017
Security Bulletin ID
SB2017011343
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2016-9401)
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d60bf515aff21d0ef3eb0cfa45d92d5ee725e755
- https://git.alpinelinux.org/aports/commit/?id=dd8f9634def3da46637cc5768d6e649e8cfa1093
- https://git.alpinelinux.org/aports/commit/?id=c39007352cac9174d8c5520f8a2f76ca78b004d7
- https://git.alpinelinux.org/aports/commit/?id=a8d4c6b2ae3c6a9fab61de635621692ded81feac
- https://git.alpinelinux.org/aports/commit/?id=88fc2ef0acfc8d5519e18e4f1965ab42eb7243b2
- https://git.alpinelinux.org/aports/commit/?id=2399dd2a5a6a24f0f1ac9580ca4683a007cc9d40