{"id":"MGASA-2021-0141","summary":"Updated ksh packages fix security vulnerability","details":"A flaw was found in the way ksh evaluates certain environment variables. An\nattacker could use this flaw to override or bypass environment restrictions to\nexecute shell commands. Services and applications that allow remote\nunauthenticated attackers to provide one of those environment variables could\nallow them to exploit this issue remotely (CVE-2019-14868).\n","modified":"2026-04-16T04:43:59.154196299Z","published":"2021-03-17T11:01:53Z","upstream":["CVE-2019-14868"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0141.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26213"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/N4R57SLEOTTXFWOLPTVVS2AOZ35FZEJR/"}],"affected":[{"package":{"name":"ksh","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/ksh?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2020.0.0.81.git8052490-0.1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0141.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}