Home > Security > Advisories

Advisories

Mandriva Advisories

Package name bash1
Date November 28th, 2000
Advisory ID MDKSA-2000:075
Affected versions 6.0, 6.1, 7.0, 7.1, 7.2
Synopsis Updated bash1 packages fix insecure creation of temporary files

Problem Description

The bash1 shell program has the same << vulnerability that tcsh has and
incorrectly creates temporary files without the O_EXCL flag. This
vulnerability does not exist in bash2 which uses the O_EXCL flag when
creating temporary files.

Updated Packages

Mandrakelinux 6.0

 8e2d74346386276fcf68e6849acc68a4  6.0/RPMS/bash1-1.14.7-19.1mdk.i586.rpm
ebb627bd7938dfde6557a8567c2afdc6  6.0/SRPMS/bash1-1.14.7-19.1mdk.src.rpm

Mandrakelinux 6.1

 fc72229f27a25d43e2ef211508e3ab4d  6.1/RPMS/bash1-1.14.7-19.1mdk.i586.rpm
ebb627bd7938dfde6557a8567c2afdc6  6.1/SRPMS/bash1-1.14.7-19.1mdk.src.rpm

Mandrakelinux 7.0

 2a111d0e36318e4a415198c4a0f2461e  7.0/RPMS/bash1-1.14.7-19.1mdk.i586.rpm
ebb627bd7938dfde6557a8567c2afdc6  7.0/SRPMS/bash1-1.14.7-19.1mdk.src.rpm

Mandrakelinux 7.1

 0b06af1bcb9707f2016b249d36837fb5  7.1/RPMS/bash1-1.14.7-21.1mdk.i586.rpm
89c2b53695fe3389c4b69634c4b2bbf9  7.1/SRPMS/bash1-1.14.7-21.1mdk.src.rpm

Mandrakelinux 7.2

 f1437127f21efc3bea9affbab164684b  7.2/RPMS/bash1-1.14.7-24.1mdk.i586.rpm
39ff29cc829e0e3922d1494f57cb9e9d  7.2/SRPMS/bash1-1.14.7-24.1mdk.src.rpm

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.