[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ale] bash critical vulnerability - update NOW!
- Subject: [ale] bash critical vulnerability - update NOW!
- From: warlord at MIT.EDU (Derek Atkins)
- Date: Sun, 28 Sep 2014 19:44:49 -0400
- In-reply-to: <CAAt=rgD+dk5NWHmdEiK1zHpNDspRuK8+mBOXxhEBeAhDqF3VxQ@mail.gmail.com> (James Sumners's message of "Wed, 24 Sep 2014 14:50:58 -0400")
- References: <CAEo=5PzyJnEKg0kkk3-uPqffgM7HxQZ9aedxMVfxMQwByRYggg@mail.gmail.com> <CAAt=rgD+dk5NWHmdEiK1zHpNDspRuK8+mBOXxhEBeAhDqF3VxQ@mail.gmail.com>
James Sumners <james.sumners at gmail.com> writes:
> The moral of this story: don't write CGI scripts in Bash.
It's more than just CGI, unfortunately. Anything that runs bash can be
hit. For example, DHCP is succeptible.
-derek
--
Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
Member, MIT Student Information Processing Board (SIPB)
URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH
warlord at MIT.EDU PGP key available