On 8/27/26 9:59 PM, Collin Funk wrote:
Sam James <[email protected]> writes:How is that different from just letting the process exit otherwise? ~/.bash_logout will be used either way. If a process writes to arbitrary bash init files, then all bets are off.Sadly, if this reporter is determined to assign a CVE to this, I don't think they will run into issues. A word of caution that it is not worthwhile to try to resolve that if they do.
My favorite was the one where someone (not this reporter) reported a
security bug in bash that essentially consisted of:
1. Change the permissions on the shell to setuid root
2. Imagine the chaos!
They wanted a CVE, too. I don't think they got one.
Chet
--
``The lyf so short, the craft so long to lerne.'' - Chaucer
``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU [email protected] http://tiswww.cwru.edu/~chet/
OpenPGP_signature.asc
Description: OpenPGP digital signature
