network redirection has been enabled
Bug #712662 reported by
Kees Cook
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
bash (Ubuntu) |
Won't Fix
|
High
|
Unassigned | ||
Karmic |
Won't Fix
|
High
|
Unassigned | ||
Lucid |
Won't Fix
|
High
|
Unassigned | ||
Maverick |
Won't Fix
|
High
|
Unassigned | ||
Natty |
Won't Fix
|
High
|
Kees Cook |
Bug Description
Binary package hint: bash
Fixing bug 215034 caused bash to gain the network redirection capabilities, which is generally considered an unsafe extension to bash. This should be disabled and stay disabled.
ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: bash 4.1-2ubuntu5
ProcVersionSign
Uname: Linux 2.6.37-12-generic x86_64
Architecture: amd64
Date: Thu Feb 3 10:30:25 2011
ProcEnviron:
LANGUAGE=en_US:en
PATH=(custom, user)
LANG=en_US.UTF-8
LC_MESSAGES=
SHELL=/bin/bash
SourcePackage: bash
Changed in bash (Ubuntu): | |
importance: | Undecided → High |
Changed in bash (Ubuntu Maverick): | |
importance: | Undecided → High |
status: | New → Confirmed |
Changed in bash (Ubuntu Lucid): | |
importance: | Undecided → High |
status: | New → Confirmed |
Changed in bash (Ubuntu Karmic): | |
status: | New → Confirmed |
importance: | Undecided → High |
Changed in bash (Ubuntu Natty): | |
milestone: | none → natty-alpha-3 |
Changed in bash (Ubuntu Natty): | |
assignee: | nobody → Matthias Klose (doko) |
Changed in bash (Ubuntu Natty): | |
milestone: | natty-alpha-3 → ubuntu-11.04-beta-1 |
Changed in bash (Ubuntu Natty): | |
assignee: | Matthias Klose (doko) → Kees Cook (kees) |
status: | Confirmed → In Progress |
Changed in bash (Ubuntu Natty): | |
milestone: | ubuntu-11.04-beta-1 → none |
Changed in bash (Ubuntu): | |
milestone: | ubuntu-11.04-beta-1 → later |
Changed in bash (Ubuntu): | |
milestone: | later → none |
status: | In Progress → Won't Fix |
assignee: | Kees Cook (kees) → nobody |
To post a comment you must log in.
This makes AppArmor confinement of services that have bash scripts hard, as the /dev/* devices are emulated by bash, and are not actually in the filesystem.