oss-sec mailing list archives

Re: Fwd: Non-upstream patches for bash


From: Jakub Wilk <jwilk () jwilk net>
Date: Mon, 29 Sep 2014 12:37:57 +0200

* Solar Designer <solar () openwall com>, 2014-09-27, 19:06:
Has anyone started reviewing bash for possible other code paths where untrusted input may hit the parser?

I haven't look at the code, but what makes me nervous is that the parser is not locale-agnostic. Here's an example how it can be exploited:
http://bugs.python.org/issue22187

--
Jakub Wilk


Current thread: