Re: Serious Bash security vulnerabilities

2014-09-26 Thread Ludovic Courtès
l...@gnu.org (Ludovic Courtès) skribis: > the other three patches I'm aware of are: > http://seclists.org/oss-sec/2014/q3/att-690/eol-pushback.patch > (from Chet), > http://seclists.org/oss-sec/2014/q3/att-712/parse-oob-4_2.patch > (seems non-contro

Re: Serious Bash security vulnerabilities

2014-09-26 Thread Ludovic Courtès
We’ve decided to merge the ‘bash-cve-2014-6271’ branch: it’s an incomplete fix, but it’s already an improvement, and it’s completely built on Hydra for x86. As for what’s next, quoting Mark on IRC: the other three patches I'm aware of are: http://seclists.org/oss-sec/2014/q3/att-69

Serious Bash security vulnerabilities

2014-09-25 Thread Ludovic Courtès
Yesterday a serious Bash vulnerability was disclosed, which led to the creation of the bash-cve-2014-6271 branch which is now half built: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271 http://seclists.org/oss-sec/2014/q3/650 http://hydra.gnu.org/jobset/gnu/bash-cve-2014-6271 Ho