[MacPorts] #45150: bash 4.3.24_0 critical security update

MacPorts noreply at macports.org
Wed Sep 24 12:09:01 PDT 2014


#45150: bash 4.3.24_0 critical security update
-------------------------+----------------------
  Reporter:  hahn.seb@…  |      Owner:  raimue@…
      Type:  defect      |     Status:  closed
  Priority:  Normal      |  Milestone:
 Component:  ports       |    Version:
Resolution:  fixed       |   Keywords:  haspatch
      Port:  bash        |
-------------------------+----------------------

Comment (by hahn.seb@…):

 Sorry about forgetting to CC the maintainer.

 Fun, for me the exploit doesn't work anymore.

 {{{
 [ ~]$ echo $BASH_VERSION
 4.3.25(1)-release
 [ ~]$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
 bash: warning: x: ignoring function definition attempt
 bash: error importing function definition for `x'
 this is a test
 }}}

-- 
Ticket URL: <https://trac.macports.org/ticket/45150#comment:4>
MacPorts <http://www.macports.org/>
Ports system for OS X


More information about the macports-tickets mailing list