Home page logo
/

oss-sec logo oss-sec mailing list archives

CVE-2014-6271: remote code execution through bash
From: Florian Weimer <fw () deneb enyo de>
Date: Wed, 24 Sep 2014 16:05:51 +0200

Stephane Chazelas discovered a vulnerability in bash, related to how
environment variables are processed: trailing code in function
definitions was executed, independent of the variable name.

In many common configurations, this vulnerability is exploitable over
the network.

Chet Ramey, the GNU bash upstream maintainer, will soon release
official upstream patches.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault