oss-sec logo

oss-sec mailing list archives

Previous By Date Next
Previous By Thread Next

CVE-2014-6271: remote code execution through bash


From: Florian Weimer <fw () deneb enyo de>
Date: 2014年9月24日 16:05:51 +0200

Stephane Chazelas discovered a vulnerability in bash, related to how
environment variables are processed: trailing code in function
definitions was executed, independent of the variable name.
In many common configurations, this vulnerability is exploitable over
the network.
Chet Ramey, the GNU bash upstream maintainer, will soon release
official upstream patches.

Previous By Date Next
Previous By Thread Next

Current thread:

AltStyle によって変換されたページ (->オリジナル) /