Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Chet Ramey
On 11/6/14, 12:02 PM, Glenn Morris wrote: > Chet Ramey wrote: > >> (The link is to >> http://git.savannah.gnu.org/cgit/bash.git/snapshot/bash-master.tar.gz). I >> cannot change the main bash webpage to include that text. > > I'm not sure what you mean by that last sentence; but just in case you

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Glenn Morris
Chet Ramey wrote: > (The link is to > http://git.savannah.gnu.org/cgit/bash.git/snapshot/bash-master.tar.gz). I > cannot change the main bash webpage to include that text. I'm not sure what you mean by that last sentence; but just in case you don't know, anyone with write access to the code repo

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Steve Simmons
On Nov 6, 2014, at 10:14 AM, Ian Jackson wrote: > Chet Ramey writes ("Re: Shellshock-vulnerable version still most obvious on > ftp.gnu.org"): >> On 11/6/14, 7:47 AM, Ian Jackson wrote: >>> But in the current environment it's looking rather quaint. We could

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Ian Jackson
Chet Ramey writes ("Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org"): > On 11/6/14, 7:47 AM, Ian Jackson wrote: > > But in the current environment it's looking rather quaint. We could > > probably provide a full tarball for each patch release. &

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Chet Ramey
On 11/6/14, 7:47 AM, Ian Jackson wrote: > Chet Ramey writes ("Re: Shellshock-vulnerable version still most obvious on > ftp.gnu.org"): >> I will put tarballs with patches in the usual places within a few days. > > Thanks, that would be very helpful. > >

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-06 Thread Ian Jackson
Chet Ramey writes ("Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org"): > I will put tarballs with patches in the usual places within a few days. Thanks, that would be very helpful. For the future, it might be worth considering whether it's really sensibl

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-05 Thread Chet Ramey
On 11/5/14, 7:35 AM, Ian Jackson wrote: > If you go to ftp://ftp.gnu.org/pub/gnu/bash/, the most obvious most > recent version of bash is this: > ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz > ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz.sig > The shellshock fix is hidden in a subdirectory:

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-05 Thread Greg Wooledge
On Wed, Nov 05, 2014 at 03:20:13PM +0100, Eric Blake wrote: > On 11/05/2014 01:35 PM, Ian Jackson wrote: > > Could there please be a new full tarball release of the patched > > version ? > > There has never been a full tarball release of any other official patch; There is a tarball of bash 3.2.48

Re: Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-05 Thread Eric Blake
On 11/05/2014 01:35 PM, Ian Jackson wrote: > If you go to ftp://ftp.gnu.org/pub/gnu/bash/, the most obvious most > recent version of bash is this: > ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz > ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz.sig > The shellshock fix is hidden in a subdirecto

Shellshock-vulnerable version still most obvious on ftp.gnu.org

2014-11-05 Thread Ian Jackson
If you go to ftp://ftp.gnu.org/pub/gnu/bash/, the most obvious most recent version of bash is this: ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3.tar.gz.sig The shellshock fix is hidden in a subdirectory: ftp://ftp.gnu.org/pub/gnu/bash/bash-4.3-patches