Re: Correction of CVE-2016-7543 is incomplete

2016-10-24 Thread Ola Lundqvist
Hi Thank you for the information. Good to know that I'm not the only one that have seen this problem. One can of course argue that the attack vector is a little odd. That is a setuid binary making system. I thought system was safe enough, but now I have learnt otherwise. Anyway I do not think di

Re: Correction of CVE-2016-7543 is incomplete

2016-10-24 Thread up201407890
Quoting "Ola Lundqvist" : This is known. I "complained" at the time, as it can be seen here: https://lists.gnu.org/archive/html/bug-bash/2015-12/msg00112.html Version: all (see note below) Hardware: all Operating system: Debian GNU Linux (but all should be affected) Compiler: gcc Hi In CVE-

Correction of CVE-2016-7543 is incomplete

2016-10-24 Thread Ola Lundqvist
Version: all (see note below) Hardware: all Operating system: Debian GNU Linux (but all should be affected) Compiler: gcc Hi In CVE-2016-7543 a problem was reported that it is possible to privilege escalate to root. The correction as seen here http://lists.gnu.org/archive/html/bug-bash/2016-10/ms