Re: Updated: bash-4.1.16-8

2014-10-02 Thread Eric Blake
On 10/02/2014 09:44 PM, Eric Blake (cygwin) wrote: > To avoid confusion, the following test unambiguously tests if you are > vulnerable to ShellShock: > $ env 'x=() { echo vulnerable; }' bash -c x > > If it prints "x: command not found", your version of bash is safe and > not subject to remote ex

[ANNOUNCEMENT] Updated: bash-4.1.16-8

2014-10-02 Thread Eric Blake (cygwin)
A new release of bash, 4.1.16-8, has been uploaded and will soon reach a mirror near you; leaving the previous version at 4.1.14-7. NEWS: = This is a minor rebuild which picks up two upstream patches to fix some parser bugs (CVE-2014-7186, CVE-2014-7187, CVE-2014-6277). These bugs were found a