Re: rbash escape vulnerability

2017-12-22 Thread Chet Ramey
On 12/21/17 2:03 PM, Drew Parker wrote: > Bash Version: 4.4 > Patch Level: 12 > Release Status: release > > Description: > In rbash v4.4.12 it is possible to escape the restricted shell by > running a program in the current directory > by setting the BASH_CMDS variable. This had currently

rbash escape vulnerability

2017-12-21 Thread Drew Parker
Configuration Information [Automatically generated, do not change]: Machine: x86_64 OS: linux-gnu Compiler: gcc Compilation CFLAGS: -DPROGRAM='bash' -DCONF_HOSTTYPE='x86_64' -DCONF_OSTYPE='linux-gnu' -DCONF_MACHTYPE='x86_64-unknown-linux-gnu' -DCONF_VENDOR='unknown' -DLOCALEDIR='/usr/share/locale'