]> code.ossystems Code Review - openembedded-core.git/commit
bash: fix CVE-2014-6271
authorRoss Burton <ross.burton@intel.com>
Thu, 25 Sep 2014 23:05:18 +0000 (00:05 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Mon, 29 Sep 2014 11:15:47 +0000 (12:15 +0100)
commiteb41d5d4eaee1c810f8e418704c110c2005d0197
tree8e0b275b9770f193ea40eda54cc6348635223c2d
parent3f0a4551969798803e019435f1f4b5e8f88bea1a
bash: fix CVE-2014-6271

CVE-2014-6271 aka ShellShock.

"GNU Bash through 4.3 processes trailing strings after function definitions in
the values of environment variables, which allows remote attackers to execute
arbitrary code via a crafted environment."

Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-extended/bash/bash-3.2.48/cve-2014-6271.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash/cve-2014-6271.patch [new file with mode: 0644]
meta/recipes-extended/bash/bash_3.2.48.bb
meta/recipes-extended/bash/bash_4.3.bb