From mboxrd@z Thu Jan 1 00:00:00 1970 From: John Darrington Subject: Re: CVE-2016-0634 code execution in Bash prompt when expanding hostname Date: Wed, 21 Sep 2016 07:20:48 +0200 Message-ID: <20160921052048.GA21274@jocasta.intra> References: <20160920205530.GA21257@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="sdtB3X0nJg68CQEu" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:38313) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmZxr-0006St-QF for guix-devel@gnu.org; Wed, 21 Sep 2016 01:21:00 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bmZxn-000537-Pm for guix-devel@gnu.org; Wed, 21 Sep 2016 01:20:59 -0400 Received: from de.cellform.com ([88.217.224.109]:56592 helo=jocasta.intra) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmZxn-00052l-H2 for guix-devel@gnu.org; Wed, 21 Sep 2016 01:20:55 -0400 Content-Disposition: inline In-Reply-To: <20160920205530.GA21257@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org --sdtB3X0nJg68CQEu Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Sep 20, 2016 at 04:55:30PM -0400, Leo Famulari wrote: Any advice on how we should handle CVE-2016-0634? =20 http://seclists.org/oss-sec/2016/q3/534 Like the comment there says, it is only a problem if the machine has alread= y been owned, so I don't see what the issue is. If there is an issue it is for the bash maintainers= to patch. J' --=20 Avoid eavesdropping. Send strong encrypted email. PGP Public key ID: 1024D/2DE827B3=20 fingerprint =3D 8797 A26D 0854 2EAB 0285 A290 8A67 719C 2DE8 27B3 See http://sks-keyservers.net or any PGP keyserver for public key. --sdtB3X0nJg68CQEu Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEUEARECAAYFAlfiGK8ACgkQimdxnC3oJ7OiKACXX3g3k5IfzTw60snDftLPiUbx CgCePHZq6wZ+qduo1/srVJUj8cQucKA= =/Iai -----END PGP SIGNATURE----- --sdtB3X0nJg68CQEu--