Re: [Twisted-Python] Security Advisory: bash remote code execution

2014-09-25 Thread Matt Haggard
> > Any web server which is serving traffic over a CGI or CGI-like interface > (including WSGI) should upgrade its version of Bash immediately. > I feel ignorant, but I'm confused about how WSGI is affected (and have failed to exploit my WSGI app). AFAICT from reading the code, Twisted's WSGIReso

Re: [Twisted-Python] Security Advisory: bash remote code execution

2014-09-25 Thread Glyph Lefkowitz
On Sep 25, 2014, at 8:09 AM, Matt Haggard wrote: > > > > Any web server which is serving traffic over a CGI or CGI-like interface > > (including WSGI) should upgrade its version of Bash immediately. > > > > I feel ignorant, but I'm confused about how WSGI is affected (and have failed > to expl

[Twisted-Python] INCOMPATIBLE CHANGE: twisted.python.threadpool

2014-09-25 Thread Glyph Lefkowitz
Hi all, (For those of you wondering about the subject, note that this message is sent in compliance with This email sent in compliance with .) I've been trying to improve the reliability of the buildbots

Re: [Twisted-Python] INCOMPATIBLE CHANGE: twisted.python.threadpool

2014-09-25 Thread weykent
On Sep 25, 2014, at 3:31 PM, Glyph Lefkowitz wrote: > So, does anyone out there have any code which makes use of the aforementioned > bad attributes of ThreadPool, whose applications would break if I removed > them? Yes. Specifically, I am maintaining this AMP responder method: @FetchThre