GNU Bash environment variables command execution

GNU Bash could allow a remote attacker to execute arbitrary commands on the system, caused by a vulnerability in code evaluating specially crafted environment variables. An attacker could exploit this vulnerability to inject and execute arbitrary shell commands on the system. IBM X-Force is aware internet wide scanning and exploitation attempts targeting this vulnerability.

Ubuntu Security Notice USN-2360-2

Ubuntu Security Notice 2360-2 – USN-2360-1 fixed vulnerabilities in Firefox. This update provides the corresponding updates for Thunderbird. Antoine Delignat-Lavaud and others discovered that NSS incorrectly handled parsing ASN.1 values. An attacker could use this issue to forge RSA certificates. Various other issues were also addressed.

Software and Security Information