From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: [PATCH 0/2] Add graft for Bash CVE-2017-5932 Date: Fri, 10 Feb 2017 16:48:21 +0100 Message-ID: <87wpcyavy2.fsf@gnu.org> References: <20170210094058.6449-1-ludo@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:37499) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ccDQy-0007vA-KR for guix-devel@gnu.org; Fri, 10 Feb 2017 10:48:29 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ccDQu-0007Dy-Nl for guix-devel@gnu.org; Fri, 10 Feb 2017 10:48:28 -0500 Received: from fencepost.gnu.org ([2001:4830:134:3::e]:47067) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ccDQu-0007Ds-KU for guix-devel@gnu.org; Fri, 10 Feb 2017 10:48:24 -0500 Received: from [193.50.110.68] (port=58796 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1ccDQu-00083C-1P for guix-devel@gnu.org; Fri, 10 Feb 2017 10:48:24 -0500 In-Reply-To: <20170210094058.6449-1-ludo@gnu.org> ("Ludovic \=\?utf-8\?Q\?Cour\?\= \=\?utf-8\?Q\?t\=C3\=A8s\=22's\?\= message of "Fri, 10 Feb 2017 10:40:56 +0100") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org Ludovic Court=C3=A8s skribis: > This patch fixes Bash CVE-2017-5932, which is a remote code execution > vulnerability triggered by file name completion and disclosed on Wednesda= y: > > https://github.com/jheyens/bash_completion_vuln/raw/master/2017-01-17.b= ash_completion_report.pdf > http://www.openwall.com/lists/oss-security/2017/02/07/9 > > I'll apply it today if there are no objections. Pushed! I recommend updating since this issue becomes a real problem in conjunction with browsers that download files without first opening a dialog box, for example. Ludo=E2=80=99.