Mandriva Linux Security Advisory 2014-232

Mandriva Linux Security Advisory 2014-232 – The function wordexp() fails to properly handle the WRDE_NOCMD flag when processing arithmetic inputs in the form of $((… “)) where … can be anything valid. The backticks in the arithmetic expression are evaluated by in a shell even if WRDE_NOCMD forbade command substitution. This allows an attacker to attempt to pass dangerous commands via constructs of the above form, and bypass the WRDE_NOCMD flag. This update fixes the issue.

Leave a Reply