Re: Correction of CVE-2016-7543 is incomplete

2016-10-24 Thread Ola Lundqvist
think disabling PS4 variable would hurt much. Or do anyone see that it is useful to set to something else than +? Maybe we can allow PS4 to be expanded to some extent, but not allow it to be expanded to execute commands? // Ola On 24 October 2016 at 18:37, wrote: > Quoting "Ola Lundqvist&q

Correction of CVE-2016-7543 is incomplete

2016-10-24 Thread Ola Lundqvist
Version: all (see note below) Hardware: all Operating system: Debian GNU Linux (but all should be affected) Compiler: gcc Hi In CVE-2016-7543 a problem was reported that it is possible to privilege escalate to root. The correction as seen here http://lists.gnu.org/archive/html/bug-bash/2016-10/ms