[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: bash vulnerability jessie



On 26/09/14 12:23 PM, Patrick Wiseman wrote:

On Sep 26, 2014 11:56 AM, "Harry Putnam" <reader@newsguy.com <mailto:reader@newsguy.com>> wrote:
>
> After an `aptitude full-upgrade' this morning.  I still get the
> `VULNERABLE' answer to `x='() { :;}; echo VULNERABLE' bash -c :'
>
> I hope that is the correct string... (extracted while googling on
> vulnerability)
>
> I did ssh to my user from the same shell I ran aptitude in to make
> sure I had a new login... but I still see `Vulnerable' in answer to
> the string above.
>
> Incidentally I get that same `Vulnerable' answer to `ksh' as well.
> After googling a bit about ksh... I haven't really found solid info
> about whether ksh is a problem too.
>
> I was a little surprised to see so little mention of this bash
> thing here too.
>
> Is this bash vulnerability not really a major concern?

I just upgraded my testing system and the vulnerability went away.

Patrick

The full vulnerability hasn't been fixed yet, according to Gnu, but the problem still requires getting access to the computer to exploit it. The fixes as they come out should be available to all supported Debian releases.


Reply to: