oss-sec mailing list archives

Re: Fwd: Non-upstream patches for bash


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Fri, 26 Sep 2014 23:47:17 -0700

FWIW, I'm pretty sure I bumped into another bad-looking and probably
exploitable parser issue; for now, I sent the details privately to
Chet, Florian, and Alexander. But the bottom line is, the parser
really shouldn't be exposed to the outside world.


Current thread: