From 56a435a001c4c33e72e4e8b412ba512b4d5fc796 Mon Sep 17 00:00:00 2001 From: Michael Tremer Date: Thu, 25 Sep 2014 19:38:23 +0200 Subject: [PATCH] bash: Import fix for CVE-2014-7169 http://www.openwall.com/lists/oss-security/2014/09/25/10 Conflicts: lfs/bash --- lfs/bash | 1 + src/patches/bash-3.2-CVE-2014-7169.patch | 11 +++++++++++ 2 files changed, 12 insertions(+) create mode 100644 src/patches/bash-3.2-CVE-2014-7169.patch diff --git a/lfs/bash b/lfs/bash index e09f91ceb5..ee1946ec01 100644 --- a/lfs/bash +++ b/lfs/bash @@ -95,6 +95,7 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/bash-4.0-profile-1.patch cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/bash-3.2-ssh_source_bash.patch cd $(DIR_APP) && patch -Np0 < $(DIR_SRC)/src/patches/bash-4.3-CVE-2014-6271.patch + cd $(DIR_APP) && patch -Np0 < $(DIR_SRC)/src/patches/bash-3.2-CVE-2014-7169.patch cd $(DIR_APP) && ./configure $(CONFIGURE_OPTIONS) cd $(DIR_APP) && make $(MAKETUNING) diff --git a/src/patches/bash-3.2-CVE-2014-7169.patch b/src/patches/bash-3.2-CVE-2014-7169.patch new file mode 100644 index 0000000000..964b91f51e --- /dev/null +++ b/src/patches/bash-3.2-CVE-2014-7169.patch @@ -0,0 +1,11 @@ +*** ../bash-20140912/parse.y 2014-08-26 15:09:42.000000000 -0400 +--- parse.y 2014-09-24 22:47:28.000000000 -0400 +*************** +*** 2959,2962 **** +--- 2959,2964 ---- + word_desc_to_read = (WORD_DESC *)NULL; + ++ eol_ungetc_lookahead = 0; ++ + current_token = '\n'; /* XXX */ + last_read_token = '\n'; -- 2.39.5