|
Message-ID: <127C3BAFC01B4F4AA1B07F6D89FF8A1612F4F4BF@G6W2502.americas.hpqcorp.net> Date: Thu, 2 Oct 2014 17:30:13 +0000 From: "Menkhus, Mark (Global Cyber Security SSRT)" <mark.menkhus@...com> To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>, Sona Sarmadi <sona.sarmadi@...a.com> CC: Solar Designer <solar@...nwall.com> Subject: RE: more bash parser bugs (CVE-2014-6277, CVE-2014-6278) Hi, What URL do I point to see the security bugs listed by CVE for CVE for bash43-25 through -28? I didn't see it in the patches themselves - ftp://ftp.cwru.edu/pub/bash/bash-4.3-patches Sorry, I am new to bash culture, Mark Menkhus Hewlett Packard -----Original Message----- From: Chet Ramey [mailto:chet.ramey@...e.edu] Sent: Thursday, October 02, 2014 8:58 AM To: Sona Sarmadi; oss-security@...ts.openwall.com Cc: Solar Designer; chet.ramey@...e.edu Subject: Re: [oss-security] more bash parser bugs (CVE-2014-6277, CVE-2014-6278) On 10/2/14, 3:22 AM, Solar Designer wrote: > Sona - Chet is not on oss-security, we should be CC'ing him on > relevant messages. I've just added the CC on this one. > > On Thu, Oct 02, 2014 at 06:48:54AM +0000, Sona Sarmadi wrote: >>> On 10/1/14, 5:04 PM, Shawn wrote: >>>> http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-028 >>> >>> Nope, this one fixes 7168/7169. It's the equivalent of the `parser-oob' patch. My mistake, it's 7186/7187. There are fixes for both in one patch. The fix for the off-by-one error is not obvious, but it's in there in the third chunk. Chet -- ``The lyf so short, the craft so long to lerne.'' - Chaucer ``Ars longa, vita brevis'' - Hippocrates Chet Ramey, ITS, CWRU chet@...e.edu http://cnswww.cns.cwru.edu/~chet/
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.