oss-sec mailing list archives

Re: CVE-2014-6271: remote code execution through bash


From: Hanno Böck <hanno () hboeck de>
Date: Wed, 24 Sep 2014 19:03:21 +0200

On Wed, 24 Sep 2014 18:30:35 +0200
Florian Weimer <fweimer () redhat com> wrote:

This depends on how PHP is invoked.  mod_php does not set the CGI 
environment variables.

However, it is true that if CGI programs spawn subprocesses, they may
be affected even if the CGI program itself is not written in bash.

Regarding php, isn't it quite common to run it through mod_fcgid with a
(bash) wrapper script? At least that's what apache wiki documents:
https://wiki.apache.org/httpd/php-fcgid

So that'd mean many php installations are affected even if they don't
use subprocesses.

I'm not sure if this wrapper can be avoided.

-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: