3 ms·
This patch script doesn't seem to fix CVE-2014-7169 (the second exploit) on some distributions. I have confirmed that the vulnerability still works after patchi
by tpfister 12y ago
This patch script doesn't seem to fix CVE-2014-7169 (the second exploit) on some distributions. I have confirmed that the vulnerability still works after patching with Debian etch and lenny installations.
I have issued an updated patcher script that fixes the patch: https://github.com/tpfister/public/blob/master/patch_shellshock_and_aftershock.sh https://github.com/tpfister/public/blob/master/patch_shellsh...
The relevant changes are:
# aftershock patch CVE-2014-7169
wget -nv http://tomas.pfister.fi/aftershock_4.3.txt http://tomas.pfister.fi/aftershock_4.3.txt
patch -p0 < aftershock_4.3.txt
After patching the second vulnerability no longer works:
tp@tp:~/src/bash-4.3$ env X='() { (a)=>\' ./bash -c "echo date"; cat echo
./bash: X: line 1: syntax error near unexpected token `='
./bash: X: line 1: `'
./bash: error importing function definition for `X'
date
cat: echo: No such file or directory
tp@tp:~/src/bash-4.3$
- shellshocker 12y agoThis is an older, more vulnerable version of BASH. Our script provides 4.3 with fixes, not 3.2
- tpfister 12y agoThe script has been updated to bash 4.3.