[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Help-bash] Patching shellshock fixes for 2.05
From: |
Chet Ramey |
Subject: |
Re: [Help-bash] Patching shellshock fixes for 2.05 |
Date: |
Thu, 02 Oct 2014 14:23:19 -0400 |
User-agent: |
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.6.0 |
On 10/2/14, 1:28 PM, Mohan Kannekanti wrote:
> Hi Team,
>
> I am trying to patch the latest fixes for 2.05 using what were given for
> 2.05b. It looks like bash took lot of changes from 2.05 to 2.05b especially
> how the environment variables are treated.
>
> I did manually patched your fixes on 2.05 version. But it looks like
> CVE-2014-7187 is still vulnerable.
I doubt it's vulnerable, since the array with the off-by-one access error
the exploit uses doesn't exist.
--
``The lyf so short, the craft so long to lerne.'' - Chaucer
``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, ITS, CWRU address@hidden http://cnswww.cns.cwru.edu/~chet/