]> code.ossystems Code Review - openembedded-core.git/commit
bash: fix CVE-2014-6271
authorRoss Burton <ross.burton@intel.com>
Thu, 25 Sep 2014 23:05:18 +0000 (00:05 +0100)
committerRobert Yang <liezhi.yang@windriver.com>
Thu, 2 Oct 2014 07:03:40 +0000 (00:03 -0700)
commit05eecceb4d2a5821cd0ca0164610e9e6d68bb22c
tree44a09ef4535a128c113a17763975720e229025ef
parent32e43d08533a20d2d8be7f6cb83360564601f4a4
bash: fix CVE-2014-6271

CVE-2014-6271 aka ShellShock.

"GNU Bash through 4.3 processes trailing strings after function definitions in
the values of environment variables, which allows remote attackers to execute
arbitrary code via a crafted environment."

(From OE-Core master rev: 798d833c9d4bd9ab287fa86b85b4d5f128170ed3)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Robert Yang <liezhi.yang@windriver.com>
meta/recipes-extended/bash/bash-3.2.48/cve-2014-6271.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash_3.2.48.bb