bash-doc - Documentation and examples for the GNU Bourne Again SHell

2016-10-09 - Salvatore Bonaccorso <>
bash (4.3-11+deb8u1) jessie; urgency=medium
* Non-maintainer upload.
* CVE-2016-0634: Arbitrary code execution via malicious hostname
* CVE-2016-7543: Specially crafted SHELLOPTS+PS4 variables allows command
2014-10-07 - Matthias Klose <>
bash (4.3-11) unstable; urgency=medium
* Apply upstream patches 028 - 030.
* Remove the parser-oob patch.
2014-09-30 - Matthias Klose <>
bash (4.3-10) unstable; urgency=medium
* Apply upstream patches 026 and 027.
* Remove patches CVE-2014-6271 and variables-affix.
2014-09-25 - Thijs Kinkhorst <>
bash (4.3-9.2) unstable; urgency=high
* Non-maintainer upload by the Security Team.
* Add variables-affix.patch patch.
Apply patch from Florian Weimer to add prefix and suffix for environment
variable names which contain shell functions.
* Add parser-oob.patch patch.
Fixes two out-of-bound array accesses in the bash parser.
2014-09-24 - Florian Weimer <>
bash (4.3-9.1) unstable; urgency=high
* Non-maintainer upload by the security team
* Apply upstream patch bash43-025, fixing CVE-2014-6271.
2014-08-21 - Matthias Klose <>
bash (4.3-9) unstable; urgency=medium
* Apply upstream patches 023 - 024, fixing the issues:
- bash does not correctly parse process substitution constructs that
contain unbalanced parentheses as part of the contained command.
- Indirect variable references do not work correctly if the reference
variable expands to an array reference using a subscript other than 0
(e.g., foo='bar[1]' ; echo ${!foo}).
* debian/skel.bashrc: Add GCC_COLORS setting (disabled by default).
2014-08-03 - Matthias Klose <>
bash (4.3-8) unstable; urgency=medium
* Apply upstream patches 012 - 022, fixing the issues:
- When a SIGCHLD trap runs a command containing a shell builtin while a
script is running `wait' to wait for all running children to complete,
the SIGCHLD trap will not be run once for each child that terminates.
- Using reverse-i-search when horizontal scrolling is enabled does not
redisplay the entire line containing the successful search results.
- Under certain circumstances, $@ is expanded incorrectly in contexts
where word splitting is not performed.
- When completing directory names, the directory name is dequoted twice.
This causes problems for directories with single and double quotes in
their names.
- An extended glob pattern containing a slash (`/') causes the globbing
code to misinterpret it as a directory separator.
- The code that creates local variables should not clear the `invisible'
attribute when returning an existing local variable.  Let the code that
actually assigns a value clear it.
- When assigning an array variable using the compound assignment syntax,
but using `declare' with the rhs of the compound assignment quoted, the
shell did not mark the variable as visible after successfully performing
the assignment.
- The -t timeout option to `read' does not work when the -e option is used.
LP: #1317476.
- When PS2 contains a command substitution, here-documents entered in an
interactive shell can sometimes cause a segmentation fault.
- When the readline `revert-all-at-newline' option is set, pressing newline
when the current line is one retrieved from history results in a double
free and a segmentation fault. Closes: #747341.
- Using nested pipelines within loops with the `lastpipe' option set can
result in a segmentation fault.
* Fix typo in package description. Closes: #707810.

