oss-sec mailing list archives
Re: Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability)
From: Loganaden Velvindron <loganaden () gmail com>
Date: Mon, 29 Sep 2014 15:17:55 +0400
On Sun, Sep 28, 2014 at 8:52 PM, Bryan Drewery <bdrewery () freebsd org> wrote:
On 2014-09-26 15:52, Bryan Drewery wrote:On 9/26/2014 9:13 AM, Christos Zoulas wrote:On Sep 26, 1:47pm, john.haxby () oracle com (John Haxby) wrote: -- Subject: Re: [oss-security] Re: CVE-2014-6271: remote code execution throu | It's not so much the known attacks -- redefining ls, unset, command, | typeset, declare, etc -- it's the future parser bugs that we don't yet | know about. | | A friend of mine said this could be a vulnerability gift that keeps on | giving. I think that at this point the conservative approach is best, so until the bash author figures what the best solution is, the feature is disabled by default for NetBSD. It is not wise to expose bash's parser to the internet and then debug it live while being attacked. christosFreeBSD has taken a similar approach. We have used Christos' patch and disabled the feature by default. https://svnweb.freebsd.org/changeset/ports/369341FYI I have updated the FreeBSD bash to 27 and modified the --import-functions script to be implicit for interactive shells and to also give a warning when functions are ignored. https://svnweb.freebsd.org/ports/head/shells/bash/files/extrapatch-import-functions?revision=369467&view=co&pathrev=369467
HI Chet, As you are aware, a sixth security issue has been discovered. Due to the nature of the vulnerability, I believe that it's best to break backward compatibility as done by FreeBSD and NetBSD until a proper patch is developed. We are lucky to have security researchers reporting their findings publicly. What about others that don't ? I strongly believe that it's much safer to have it disabled, and have a complete and comprehensive audit of the source code, and then re-enable it.
-- Regards, Bryan Drewery
-- This message is strictly personal and the opinions expressed do not represent those of my employers, either past or present.
Current thread:
- Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Mark R Bannister (Sep 26)
- <Possible follow-ups>
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Hanno Böck (Sep 26)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Florian Weimer (Sep 26)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) John Haxby (Sep 26)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Bernhard Hermann (Sep 26)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Christos Zoulas (Sep 26)
- Re: Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Bryan Drewery (Sep 26)
- Re: Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Bryan Drewery (Sep 28)
- Re: Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Loganaden Velvindron (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Giles Coochey (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Michal Zalewski (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Michal Zalewski (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Osmond Sun (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Chet Ramey (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Kobrin, Eric (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Chet Ramey (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) John Haxby (Sep 26)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Osmond Sun (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Giles Coochey (Sep 29)
- Re: Re: CVE-2014-6271: remote code execution through bash (3rd vulnerability) Chet Ramey (Sep 29)