Daily Shaarli

All links of one day in a single page.

September 24, 2014

oss-sec: CVE-2014-6271: remote code execution through bash
thumbnail

Stephane Chazelas discovered a vulnerability in bash, related to how
environment variables are processed: trailing code in function
definitions was executed, independent of the variable name.

In many common configurations, this vulnerability is exploitable over
the network.