]> code.ossystems Code Review - openembedded-core.git/commit
bash: fix CVE-2014-6271
authorRoss Burton <ross.burton@intel.com>
Thu, 25 Sep 2014 23:05:18 +0000 (00:05 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 29 Sep 2014 11:12:35 +0000 (12:12 +0100)
commit798d833c9d4bd9ab287fa86b85b4d5f128170ed3
tree6855ca3f2cc53f007d5ac4d1972312302ce76821
parent8521d4d6b73c93ae60cca3d04673cdd02c27446c
bash: fix CVE-2014-6271

CVE-2014-6271 aka ShellShock.

"GNU Bash through 4.3 processes trailing strings after function definitions in
the values of environment variables, which allows remote attackers to execute
arbitrary code via a crafted environment."

Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-extended/bash/bash-3.2.48/cve-2014-6271.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash/cve-2014-6271.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash_3.2.48.bb
meta/recipes-extended/bash/bash_4.3.bb