OESA-2022-2100

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-2100
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-2100.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2022-2100
Upstream
Published
2022-11-18T11:04:37Z
Modified
2025-08-12T05:14:36.076641Z
Summary
bash security update
Details

Bash is the GNU Project's shell. Bash is the Bourne Again SHell. Bash is an sh-compatible shell that incorporates useful features from the Korn shell (ksh) and C shell (csh). It is intended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers functional improvements over sh for both programming and interactive use. In addition, most sh scripts can be run by Bash without modification.

Security Fix(es):

A flaw was found in the bash package, where a heap-buffer overflow can occur in validparametertransform. This issue may lead to memory problems.(CVE-2022-3715)

Database specific
{
    "severity": "Low"
}
References

Affected packages

openEuler:22.03-LTS / bash

Package

Name
bash
Purl
pkg:rpm/openEuler/bash&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.8-6.oe2203

Ecosystem specific

{
    "src": [
        "bash-5.1.8-6.oe2203.src.rpm"
    ],
    "noarch": [
        "bash-help-5.1.8-6.oe2203.noarch.rpm"
    ],
    "aarch64": [
        "bash-debugsource-5.1.8-6.oe2203.aarch64.rpm",
        "bash-devel-5.1.8-6.oe2203.aarch64.rpm",
        "bash-debuginfo-5.1.8-6.oe2203.aarch64.rpm",
        "bash-5.1.8-6.oe2203.aarch64.rpm"
    ],
    "x86_64": [
        "bash-debugsource-5.1.8-6.oe2203.x86_64.rpm",
        "bash-debuginfo-5.1.8-6.oe2203.x86_64.rpm",
        "bash-5.1.8-6.oe2203.x86_64.rpm",
        "bash-devel-5.1.8-6.oe2203.x86_64.rpm"
    ]
}