File _patchinfo of Package patchinfo.7219
<patchinfo incident="7219">
<issue id="1086247" tracker="bnc">bash-4.3 misbehavior in "trap"</issue>
<issue id="1001299" tracker="bnc">VUL-1: CVE-2016-7543: bash SHELLOPTS+PS4</issue>
<issue id="1000396" tracker="bnc">VUL-1: CVE-2016-0634: bash: Arbitrary code execution via malicious hostname</issue>
<issue id="2016-7543" tracker="cve"></issue>
<issue id="2016-0634" tracker="cve"></issue>
<category>security</category>
<rating>moderate</rating>
<packager>WernerFink</packager>
<description>This update for bash fixes the following issues:
Security issues fixed:
- CVE-2016-7543: A code execution possibility via SHELLOPTS+PS4 variable was fixed (bsc#1001299)
- CVE-2016-0634: Arbitrary code execution via malicious hostname was fixed (bsc#1000396)
Non-security issues fixed:
- Fix repeating self-calling of traps due the combination of a non-interactive shell, a trap handler for SIGINT, an
external process in the trap handler, and a SIGINT within the trap after the external process runs. (bsc#1086247)
</description>
<summary>Security update for bash</summary>
</patchinfo>