oss-sec mailing list archives

Re: CVE-2014-6271: remote code execution through bash


From: Hanno Böck <hanno () hboeck de>
Date: Wed, 24 Sep 2014 23:27:09 +0200

Tavis Ormandy just tweetet this:
https://twitter.com/taviso/status/514887394294652929

The bash patch seems incomplete to me, function parsing is still
brittle. e.g. $ env X='() { (a)=>\' sh -c "echo date"; cat echo


-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: