oss-sec mailing list archives

Re: CVE-2014-6271: remote code execution through bash


From: Henri Salo <henri () nerv fi>
Date: Wed, 24 Sep 2014 18:54:50 +0300

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Sep 24, 2014 at 07:16:20PM +0400, Solar Designer wrote:
Florian posted a Debian security advisory on this ([DSA 3032-1] bash
security update) to the debian-security-announce list, but somehow it is
not yet seen at:

https://www.debian.org/security/
https://lists.debian.org/debian-security-announce/2014/

(I guess it will be very soon.)

It will take some time that /security/ URL gets updated. Latest information
about CVEs can be seen here:

https://security-tracker.debian.org/tracker/CVE-2014-6271

- ---
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlQi6UoACgkQXf6hBi6kbk/L9wCggJR1kzvxv787MrjwSAK8o/Nz
aA4AnjtrbddPB1fp+CvwB9JPWXHX+lS+
=PX64
-----END PGP SIGNATURE-----


Current thread: