Debian Security Advisory

DLA-59-1 bash -- LTS security update

Date Reported:
24 Sep 2014
Affected Packages:
bash
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-6271.
More information:

Stephane Chazelas discovered a vulnerability in bash, the GNU Bourne-Again Shell, related to how environment variables are processed. In many common configurations, this vulnerability is exploitable over the network, especially if bash has been configured as the system shell.

For Debian 6 Squeeze, these issues have been fixed in bash version 4.1-3+deb6u1