On 8/27/26 9:59 PM, Collin Funk wrote:
Sam James <[email protected]> writes:

How is that different from just letting the process exit otherwise?
~/.bash_logout will be used either way. If a process writes to arbitrary
bash init files, then all bets are off.

Sadly, if this reporter is determined to assign a CVE to this, I don't
think they will run into issues. A word of caution that it is not
worthwhile to try to resolve that if they do.

My favorite was the one where someone (not this reporter) reported a
security bug in bash that essentially consisted of:

1. Change the permissions on the shell to setuid root
2. Imagine the chaos!

They wanted a CVE, too. I don't think they got one.

Chet

--
``The lyf so short, the craft so long to lerne.'' - Chaucer
                 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU    [email protected]    http://tiswww.cwru.edu/~chet/

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

  • [SECURIT... correspondence2--- via Bug reports for the GNU Bourne Again SHell

Reply via email to