[Bug 1374207] Re: CVE-2014-7169 fix not effective on trusty

2014-09-26 Thread Thomas Muthmann
Hi Seth, thanks to figuring this out so fast. I had indeed a 0 bytes file /root/echo from an earlier test. So my entry #8 can be discarded. Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1374207

[Bug 1374207] Re: CVE-2014-7169 fix not effective on trusty

2014-09-26 Thread Thomas Muthmann
Fix does not work in every directory Using Trusty and 4.3-7ubuntu1.3 sudo -i cd /root X='() { function a a>\' bash -c echo; [ -e echo ] && echo "hacked" bash: X: line 1: syntax error near unexpected token `a' bash: X: line 1: `' bash: error importing function definition for `X' hacked cd /bin