Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
First patch for Shellshock may not be a complete fix (itnews.com.au)
2 points by arash_milani on Sept 25, 2014 | hide | past | favorite | 1 comment


From the article:

β€œIt looks like the patch does not fix every case of environment variables being used to pass on executable code. We are still testing the patch, and hope to have more information on it soon,” Boileau said.

A number of other security experts highlighted the incomplete nature of the fix on the Red Hat Bugzilla page. https://bugzilla.redhat.com/show_bug.cgi?id=1141597#c23




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: