Re: Potential vulnerabilities in BASH 4.3

2014-08-12 Thread Chet Ramey
> > bash-4.3.tar\bash-4.3\lib\sh\unicode.c: > > *line 87: *strcpy (charsetbuf, locale); > > Thanks for the report. This is a potential vulnerability if the value of > the LC_CTYPE variable is longer than 40 characters. I should have added that this is only a problem on systems that don't have an

Re: Potential vulnerabilities in BASH 4.3

2014-08-12 Thread Chet Ramey
On 8/11/14, 3:07 PM, Hádrian R wrote: > Hi, I'm Hádrien Romero Soria - @Kaiwaiata​​, I am a 16 year old boy, > passionate about computer security, since more than 8h searching and > finding various possible vulnerabilities in source code of bash.. > I will tell you one vulnerability now, if they tr

Re: Potential vulnerabilities in BASH 4.3

2014-08-11 Thread Mike Frysinger
On Mon 11 Aug 2014 21:07:06 Hádrian R wrote: > Hi, I'm Hádrien Romero Soria - @Kaiwaiata​​, I am a 16 year old boy, > passionate about computer security, since more than 8h searching and > finding various possible vulnerabilities in source code of bash.. > I will tell you one vulnerability now, if

Potential vulnerabilities in BASH 4.3

2014-08-11 Thread Hádrian R
Hi, I'm Hádrien Romero Soria - @Kaiwaiata​​, I am a 16 year old boy, passionate about computer security, since more than 8h searching and finding various possible vulnerabilities in source code of bash.. I will tell you one vulnerability now, if they treat me well I will tell the other.. foolish o