CVE-2009-0854

Publication date 11 March 2009

Last updated 24 July 2024


Ubuntu priority

Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.

Read the notes from the security team

Status

Package Ubuntu Release Status
dash 8.10 intrepid
Fixed 0.5.4-9ubuntu1.1
8.04 LTS hardy
Fixed 0.5.4-8ubuntu1.1
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

Ubuntu specific patch to implement -l

References

Related Ubuntu Security Notices (USN)

Other references