{"id":"MGASA-2021-0288","summary":"Updated bash packages fix a security vulnerability","details":"A privilege escalation vulnerability was found in bash in the way it dropped\nprivileges when started with an effective user id not equal to the real user\nid. Bash may be vulnerable to this flaw if the setuid permission is set and\nthe owner of the bash program itself is a non-root user. A local attacker\ncould exploit this flaw to escalate their privileges on the system\n(CVE-2019-18276).\n","modified":"2026-04-16T04:43:28.795718108Z","published":"2021-06-28T21:16:35Z","upstream":["CVE-2019-18276"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0288.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28937"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2021:1679"}],"affected":[{"package":{"name":"bash","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/bash?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4-23.1.2.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0288.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}