oss-sec mailing list archives

Re: CVE-2014-6271: remote code execution through bash


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Wed, 24 Sep 2014 09:23:10 -0700

Note that on Linux systems where /bin/sh is symlinked to /bin/bash,
any popen() / system() calls from within languages such as PHP would
be of concern due to the ability to control HTTP_* in the env.

/mz


Current thread: