#17978: bash patch for shellshock vulnerability
------------------------+------------------------
  Reporter:  anonymous  |      Owner:  developers
      Type:  defect     |     Status:  new
  Priority:  highest    |  Milestone:
 Component:  packages   |    Version:  Trunk
Resolution:             |   Keywords:
------------------------+------------------------

Comment (by anonymous):

 The proposed fix doesn't address the situation fully, this still works :

 env X='() { (a)=>\' sh -c "echo date"; cat echo

 Also it '''works with /bin/ash''', this would indicate that ash would also
 need to be patched...

--
Ticket URL: <https://dev.openwrt.org/ticket/17978#comment:1>
OpenWrt <http://openwrt.org>
Opensource Wireless Router Technology
_______________________________________________
openwrt-tickets mailing list
[email protected]
https://lists.openwrt.org/cgi-bin/mailman/listinfo/openwrt-tickets

Reply via email to