[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Bash security issue
From: |
Nick Bowler |
Subject: |
Re: Bash security issue |
Date: |
Thu, 25 Sep 2014 13:21:58 -0400 |
User-agent: |
Mutt/1.5.22 (2013-10-16) |
On 2014-09-25 08:55 -0600, Eric Blake wrote:
> On 09/25/2014 07:51 AM, Bob Friesenhahn wrote:
> > It may be that some users of 'autoconf' will be at risk due to the dire
> > bash security bug described at
> > "http://www.theregister.co.uk/2014/09/24/bash_shell_vuln/".
> >
> > Take care that the environment is carefully vetted.
>
> There's nothing that ./configure can do to avoid the buggy bash, but it
> may indeed be worth patching autoconf to generate configure scripts that
> issue a loud warning if the buggy shell is detected on the user's
> system. I'll look into doing that.
The most surprising thing I learned from this whole ordeal is that
there are strings consisting entirely of printable characters that
are not portable to store in exported shell variables.
Cheers,
--
Nick Bowler, Elliptic Technologies (http://www.elliptictech.com/)
- Re: Bash security issue, (continued)
- Re: Bash security issue, Ralf Corsepius, 2014/09/29
- Re: Bash security issue, Eric Blake, 2014/09/29
- Re: Bash security issue, Ralf Corsepius, 2014/09/29
- Re: Bash security issue, Paul Eggert, 2014/09/29
- Re: Bash security issue, Henrique de Moraes Holschuh, 2014/09/29
- Re: Bash security issue, Eric Blake, 2014/09/29
- Re: Bash security issue, Nick Bowler, 2014/09/29
Re: Bash security issue, Bob Friesenhahn, 2014/09/25
Re: Bash security issue,
Nick Bowler <=
- Re: Bash security issue, Eric Blake, 2014/09/25
- Re: Bash security issue, Linda Walsh, 2014/09/25
- Re: Bash security issue, Eric Blake, 2014/09/25
- Re: Bash security issue, Linda Walsh, 2014/09/26
- Re: Bash security issue, lolilolicon, 2014/09/26
- Re: Bash security issue, Zack Weinberg, 2014/09/26
- Re: Bash security issue, Eric Blake, 2014/09/26
- Re: Bash security issue, Steve Simmons, 2014/09/26
- Re: Bash security issue, Paul Smith, 2014/09/26
- Re: Bash security issue, Chet Ramey, 2014/09/27