FlawAtlas
Search the atlas
SUSE-SU-2018:1398-1 Not scored

Security update for bash

This update for bash fixes the following issues: Security issues fixed: - CVE-2016-7543: A code execution possibility via SHELLOPTS+PS4 variable was fixed (bsc#1001299) - CVE-2016-0634: Arbitrary code execution via malicious hostname was fixed (bsc#1000396) Non-security issues fixed: - Fix repeating self-calling of traps due the combination of a non-interactive shell, a trap handler for SIGINT, an external process in the trap handler, and a SIGINT within the trap after the external process runs. (bsc#1086247)

Exploit probability Not scored
Published May 23, 2018
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 4 bash
SUSE:Linux Enterprise Desktop 12 SP3 bash
SUSE:Linux Enterprise Server 12 SP2-LTSS bash
SUSE:Linux Enterprise Server 12 SP3 bash
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 bash
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 bash
SUSE:Linux Enterprise Software Development Kit 12 SP3 bash
SUSE:Linux Enterprise Workstation Extension 12 SP3 bash
SUSE:OpenStack Cloud 7 bash

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:1398-1

This update for bash fixes the following issues: Security issues fixed: - CVE-2016-7543: A code execution possibility via SHELLOPTS+PS4 variable was fixed (bsc#1001299) - CVE-2016-0634: Arbitrary code execution via malicious hostname was fixed (bsc#1000396) Non-security issues fixed: - Fix repeating self-calling of traps due the combination of a non-interactive shell, a trap handler for SIGINT, an external process in the trap handler, and a SIGINT within the trap after the external process runs. (bsc#1086247)

View original source

05 / REFERENCES

Further evidence