Re: CVE-2014-6277, CVE-2014-6278

2014-09-29 Thread Henrique de Moraes Holschuh
On Mon, 29 Sep 2014, john wrote: > So I am confused. I think what I am reading here is that if you applied > the latest patches to bash [3] you are not vulnerable to CVE-2014-6277. > CVE-2014-6278. Running the test outlined on Icamtuf.blogspot.co.nz [4] > seemed to confirm that. AFAIK, we are stil

CVE-2014-6277, CVE-2014-6278

2014-09-29 Thread john
Hi all, I see there are two new CVE's for bash: CVE-2014-6277[1], CVE-2014-6278[2]. I note that the security tracker shows all versions of debian as "vulnerable" however the Notes section on 6277, 6278 shows: "The underlying parser flaw has not yet been disclosed and might still exist in latest r

RE: [SECURITY] [DSA 3035-1] bash security update

2014-09-29 Thread Anthony MOLL
Je pense que les firewall Netasq sont impacter par cette faille de sécurité. Anthony -Message d'origine- De : Salvatore Bonaccorso [mailto:car...@debian.org] Envoyé : jeudi 25 septembre 2014 23:19 À : debian-security-annou...@lists.debian.org Objet : [SECURITY] [DSA 3035-1] bash security