Skip to content
This repository was archived by the owner on Nov 9, 2017. It is now read-only.
This repository was archived by the owner on Nov 9, 2017. It is now read-only.

Bash Remote Exploit Vulnerability via env. var [CVE-2014-6271 / CVE-2014-7169] #253

@mchubby

Description

@mchubby

A vulnerability in Bash up to 4.3 was discovered and allows for remote execution by defining a user-controlled environment variable to a specially crafted function definition.

While the attack surface is probably very limited in a desktop scenario (it would happen when a script is spawned by mod_cgi, for instance), it would still be a good idea to plug the hole.

As of this writing, an incomplete fix was released for CVE-2014-6271; I suggest waiting for a revised solution.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions