• [^] # Re: CVE-2014-6271

    Posté par . En réponse au journal Mets à jour ton bash. Maintenant.. Évalué à 1.

    et sa correction debian : https://www.debian.org/security/2014/dsa-3035

    Tavis Ormandy discovered that the patch applied to fix CVE-2014-6271 released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was incomplete and could still allow some characters to be injected into another environment (CVE-2014-7169). With this update prefix and suffix for environment variable names which contain shell functions are added as hardening measure.

    Donc si vous avez mis à jour bash hier (jeudi), vous pouvez recommencer ce matin (vendredi).

    Vous pouvez également regarder cette vidéo http://www.youtube.com/watch?v=ArEOVHQu9nk&feature=youtu.be qui donne des explications sur comment on peut exploiter cette faille avec apache/cgi