oss-sec mailing list archives

Re: CVE-2014-6271: remote code execution through bash


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Thu, 25 Sep 2014 12:53:35 -0700

Yeah, that general approach is probably the best.  I was just wondering.
I don't really see the need to use a prefix and a suffix, though.

Prefix is definitely more valuable, because specific prefixes are
enforced by Apache and its ilk, but the suffix for the HTTP header ->
shell variable propagation is within attacker's control.

/mz


Current thread: