FEDORA-2014-11718 created by ooprala 7 years ago for Fedora 21
stable

Fix for cve-2014-7169

You can use this test: env X='() { (a)=>' sh -c "OVERWRITE echo 'File OVERWRITE now contains this sentence.'"

How to install

sudo dnf upgrade --advisory=FEDORA-2014-11718

This update has been submitted for testing by ooprala. This critical path update has not yet been approved for pushing to the stable repository. It must first reach a karma of 2, consisting of 0 positive karma from proventesters, along with 2 additional karma from the community. Or, it must spend 14 days in testing without any negative feedback

7 years ago

AutoQA: depcheck test PASSED on i386. Result log: http://autoqa.fedoraproject.org/report/1hca2 (results are informative only)

AutoQA: depcheck test PASSED on x86_64. Result log: http://autoqa.fedoraproject.org/report/1hca5 (results are informative only)

User Icon bitlord commented & provided feedback 7 years ago
karma

If command not found is expected result for the test case, then it works.

Critical path update approved

7 years ago
User Icon lmacken commented & provided feedback 7 years ago
karma

Test yields command not found

User Icon ryanlerch commented & provided feedback 7 years ago
karma

Test returns -- "sh: OVERWRITE: command not found"

This update has reached the stable karma threshold and will be pushed to the stable updates repository

7 years ago

To confirm: OVERWRITE: command not found is expected "fix works!" result. Unless you have an actual command on your system for some reason. :)

User Icon kalev commented & provided feedback 7 years ago
karma

No regressions noted in brief testing and the OVERWRITE testcase now passes.

AutoQA: upgradepath test PASSED on noarch. Result log: http://autoqa.fedoraproject.org/report/1hcap (results are informative only)

User Icon pbrady provided feedback 7 years ago
karma
User Icon pnemade commented & provided feedback 7 years ago
karma

I see the output "sh: OVERWRITE: command not found"

User Icon nonamedotc commented & provided feedback 7 years ago
karma

Works well. "sh: OVERWRITE: command not found"

User Icon mstevens commented & provided feedback 7 years ago
karma

works fine

User Icon amsharma commented & provided feedback 7 years ago
karma

tested, worked fine.

User Icon cicku provided feedback 7 years ago
karma

This update is currently being pushed to the Fedora 21 stable updates repository.

7 years ago

This update has been pushed to stable

7 years ago

Please login to add feedback.

Metadata
Type
security
Karma
10
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
7 years ago
in stable
7 years ago
BZ#1146319 CVE-2014-7169 bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
0
0

Automated Test Results