Tavis Ormandy discovered that the patch applied to fix CVE-2014-6271 released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was incomplete and could still allow some characters to be injected into another environment (CVE-2014-7169). With this update prefix and suffix for environment variable names which contain shell functions are added as hardening measure.
Donc si vous avez mis à jour bash hier (jeudi), vous pouvez recommencer ce matin (vendredi).
[^] # Re: CVE-2014-6271
Posté par Matthieu . En réponse au journal Mets à jour ton bash. Maintenant.. Évalué à 1.
et sa correction debian : https://www.debian.org/security/2014/dsa-3035
Donc si vous avez mis à jour bash hier (jeudi), vous pouvez recommencer ce matin (vendredi).
Vous pouvez également regarder cette vidéo http://www.youtube.com/watch?v=ArEOVHQu9nk&feature=youtu.be qui donne des explications sur comment on peut exploiter cette faille avec apache/cgi