USN-2363-1 fixed a vulnerability in Bash. Due to a build issue, the patch for CVE-2014-7169 didn't get properly applied in the Ubuntu 14.04 LTS package. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Tavis Ormandy discovered that the security fix for Bash included in USN-2362-1 was incomplete. An attacker could use this issue to bypass certain environment restrictions. (CVE-2014-7169)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.3-7ubuntu1.3", "binary_name": "bash" }, { "binary_version": "4.3-7ubuntu1.3", "binary_name": "bash-builtins" }, { "binary_version": "4.3-7ubuntu1.3", "binary_name": "bash-doc" }, { "binary_version": "4.3-7ubuntu1.3", "binary_name": "bash-static" } ] }