Bug 1149626

Summary: mksh: do not permit += from environment
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: carnil, fweimer, mhlavink, redhat-bugzilla
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mksh R50c Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-02-15 09:20:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1149627    
Bug Blocks: 1149631    

Description Vasyl Kaigorodov 2014-10-06 09:42:25 UTC
mksh version R50c fixes a security issue.
Excerpt from ChangeLog [1]:
...
[tg] SECURITY: do not permit += from environment
...

Upstream commit is at [2]

[1]: https://www.mirbsd.org/mksh.htm#clog
[2]: https://github.com/MirBSD/mksh/commit/de53d2df1c3b812c262cc1bddbfe0b3bfc25c14b

Comment 1 Vasyl Kaigorodov 2014-10-06 09:43:21 UTC
Created mksh tracking bugs for this issue:

Affects: fedora-all [bug 1149627]

Comment 2 Robert Scheck 2014-10-06 09:46:17 UTC
Is this issue now worth a CVE even upstream was initially told that it is too
minor? Or is this going to be just a RHBZ without CVE?

Comment 3 Robert Scheck 2014-10-06 09:51:01 UTC
(In reply to Vasyl Kaigorodov from comment #1)
> Affects: fedora-all [bug 1149627]

IMHO an epel-5 tracking bug is missing, however I now used the fedora-all for
EL-5 (the updates are anyway in testing since last week). And this issue should
also affect RHEL 7 but not RHEL 6 if not mistaken (I don't see any reference as
of writing).

Comment 4 Vasyl Kaigorodov 2014-10-06 13:29:18 UTC
(In reply to Robert Scheck from comment #2)
> Is this issue now worth a CVE even upstream was initially told that it is too
> minor? Or is this going to be just a RHBZ without CVE?

Robert, do you have a link to the thread where upstream was told this handy?
I did not check sources thoroughly, thus not sure what the possible impact here (looks Low-to-nothing for me right now).

If it was some private communication - please let me know, I will post a CVE request to oss-sec, and we will see where it gets then.

Comment 5 Robert Scheck 2014-10-06 13:36:49 UTC
(In reply to Vasyl Kaigorodov from comment #4)
> Robert, do you have a link to the thread where upstream was told this handy?
> I did not check sources thoroughly, thus not sure what the possible impact
> here (looks Low-to-nothing for me right now).
> 
> If it was some private communication - please let me know, I will post a CVE
> request to oss-sec, and we will see where it gets then.

This question results from a discussion of mine with upstream once I was told
about the update. I hope I didn't get upstream wrong (if so, I am sorry), but
https://www.mirbsd.org/permalinks/wlog-10_e20141003-tg.htm (which is the blog
of upstream) seems to confirm my state of information in general at least. If
I get the IRC backlog right the developer is unavailable today thus I can not 
ask for a clarification or details for the moment.

Comment 6 Fedora Update System 2014-10-10 16:00:29 UTC
mksh-50c-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2014-10-10 16:07:26 UTC
mksh-50c-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2014-10-10 16:08:12 UTC
mksh-50c-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2014-10-19 03:59:52 UTC
mksh-50c-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Tomas Hoger 2016-02-15 09:20:35 UTC
It seems this issue was only introduced via the following commit, which adds support for += syntax:

https://github.com/MirBSD/mksh/commit/4345dd1fb8e3b51195d8bd260c563a697182d304

Based on the git tags, only version R40b can be affected.  The version in Red Hat Enterprise Linux 6 is 39 and unaffected.  There's currently no plan to backport the fix to Red Hat Enterprise Linux 7 packages.