oss-sec mailing list archives

Re: Fwd: Non-upstream patches for bash


From: Marc Deslauriers <marc.deslauriers () canonical com>
Date: Thu, 25 Sep 2014 18:13:08 -0400

On 14-09-25 01:49 PM, Huzaifa Sidhpurwala wrote:
Hi All,

Based on the current situation and the fact that there is confusion about what
patch to use for the bash issue. I wanted to post this here.

We have found a few more issues (OOB memory access). Also I am posting Florain's
patch here which should fix the issue in a more deeper way rather than just
apply duct-tape.


Could we please get two CVE numbers assigned for the two OOB memory issues?

Thanks,

Marc.



Current thread: