[MacPorts] #45162: bash @4.3.25: Vulnerable to code execution in environment variables (CVE-2014-7169)

MacPorts noreply at macports.org
Sat Sep 27 00:12:20 PDT 2014


#45162: bash @4.3.25: Vulnerable to code execution in environment variables
(CVE-2014-7169)
------------------------+----------------------
  Reporter:  kost.hc@…  |      Owner:  raimue@…
      Type:  defect     |     Status:  assigned
  Priority:  High       |  Milestone:
 Component:  ports      |    Version:  2.3.1
Resolution:             |   Keywords:
      Port:  bash       |
------------------------+----------------------

Comment (by brian.reiter@…):

 The NetBSD and FreeBSD solution is an excellent mitigation. It removes the
 whole misfeature of passing function definitions to child shells by
 default.

 https://svnweb.freebsd.org/ports?view=revision&revision=369341

-- 
Ticket URL: <https://trac.macports.org/ticket/45162#comment:11>
MacPorts <http://www.macports.org/>
Ports system for OS X


More information about the macports-tickets mailing list