[ale] bash critical vulnerability - update NOW!

Derek Atkins warlord at MIT.EDU
Sun Sep 28 19:44:49 EDT 2014


James Sumners <james.sumners at gmail.com> writes:

> The moral of this story: don't write CGI scripts in Bash.

It's more than just CGI, unfortunately.  Anything that runs bash can be
hit.  For example, DHCP is succeptible.

-derek
-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord at MIT.EDU                        PGP key available


More information about the Ale mailing list