oss-sec mailing list archives
Re: CVE-2014-6271: remote code execution through bash
From: Hanno Böck <hanno () hboeck de>
Date: Wed, 24 Sep 2014 19:03:21 +0200
On Wed, 24 Sep 2014 18:30:35 +0200 Florian Weimer <fweimer () redhat com> wrote:
This depends on how PHP is invoked. mod_php does not set the CGI environment variables. However, it is true that if CGI programs spawn subprocesses, they may be affected even if the CGI program itself is not written in bash.
Regarding php, isn't it quite common to run it through mod_fcgid with a (bash) wrapper script? At least that's what apache wiki documents: https://wiki.apache.org/httpd/php-fcgid So that'd mean many php installations are affected even if they don't use subprocesses. I'm not sure if this wrapper can be avoided. -- Hanno Böck http://hboeck.de/ mail/jabber: hanno () hboeck de GPG: BBB51E42
Attachment:
signature.asc
Description:
Current thread:
- Re: CVE-2014-6271: remote code execution through bash, (continued)
- Re: CVE-2014-6271: remote code execution through bash Tim (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Rich Felker (Sep 25)
- Re: CVE-2014-6271: remote code execution through bash Chet Ramey (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash mancha (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Chet Ramey (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Solar Designer (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Chet Ramey (Sep 25)
- Re: CVE-2014-6271: remote code execution through bash Alan J. Wylie (Sep 26)
- Re: CVE-2014-6271: remote code execution through bash Florian Weimer (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Hanno Böck (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Florian Weimer (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Solar Designer (Sep 24)
- Re: CVE-2014-6271: remote code execution through bash Jason Cooper (Sep 25)
- Re: CVE-2014-6271: remote code execution through bash Solar Designer (Sep 25)
- Re: CVE-2014-6271: remote code execution through bash Jason Cooper (Sep 25)