You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Nov 9, 2017. It is now read-only.
Repository navigation
This repository was archived by the owner on Nov 9, 2017. It is now read-only.
Bash Remote Exploit Vulnerability via env. var [CVE-2014-6271 / CVE-2014-7169] #253
A vulnerability in Bash up to 4.3 was discovered and allows for remote execution by defining a user-controlled environment variable to a specially crafted function definition.
While the attack surface is probably very limited in a desktop scenario (it would happen when a script is spawned by mod_cgi, for instance), it would still be a good idea to plug the hole.
As of this writing, an incomplete fix was released for CVE-2014-6271; I suggest waiting for a revised solution.
A vulnerability in Bash up to 4.3 was discovered and allows for remote execution by defining a user-controlled environment variable to a specially crafted function definition.
While the attack surface is probably very limited in a desktop scenario (it would happen when a script is spawned by mod_cgi, for instance), it would still be a good idea to plug the hole.
As of this writing, an incomplete fix was released for CVE-2014-6271; I suggest waiting for a revised solution.