![]() |
Sailfish OS bash shell is affected by the #shellshock bug
Pretty nasty this fella, here is more info and a test:
http://prng.net/shellshock/ I also filed a bug report @together, please vote: https://together.jolla.com/question/...hellshock-bug/ |
Re: Sailfish OS bash shell is affected by the #shellshock bug
fix will be included in upcoming sailfish update, you can be sure ;)
|
Re: Sailfish OS bash shell is affected by the #shellshock bug
So how exactly do you plan to exploit this vulnerability on Jolla?
What I would like to see is an upgrade to GPLv3 Bash4, instead of wasting more time on their bash3 fork. |
Re: Sailfish OS bash shell is affected by the #shellshock bug
Quote:
|
Re: Sailfish OS bash shell is affected by the #shellshock bug
@javispedro there are should be some internals accepting environment variables.
|
Re: Sailfish OS bash shell is affected by the #shellshock bug
Quote:
Quote:
Virtually the only situations where this bug can cause trouble is everywhere where a backlist/whitelist of environment variables is used to filter out such variables by name only. Because with this bug there are no "safe" env variable names. |
Re: Sailfish OS bash shell is affected by the #shellshock bug
Well, You are probably right, but this is exploitable on several applications aswell. There is a bit more here http://seclists.org/oss-sec/2014/q3/650.
So, applications that expose some of the functionality that is vulnerable (abitrary environment variables) could be used to get at least shell code execution as current user. But, that being said, I agree, I dont consider this a huge threat to Jolla/SailfishOS |
Re: Sailfish OS bash shell is affected by the #shellshock bug
Quote:
*No, running sshd alone does not mean you're vulnerable. If on the other hand you were expecting that people ssh'ing would not be able to run arbitrary code you're in for a nasty surprise (e.g. stupid centralized Git servers, sftp-only servers -- shared hosting, etc.) |
Re: Sailfish OS bash shell is affected by the #shellshock bug
anyway, waiting for bash update in nieldk repo :)
|
Re: Sailfish OS bash shell is affected by the #shellshock bug
Quote:
1) Grab all of your address book contacts, 2) Send compromising SMSs to all of them (plus a few "premium service" SMSs to inflate your bills!), 3) Zip your documents folder and upload to some chinese WWW server, 4) Then proceed to write randomly over your eMMC _permanently_ bricking the Jolla. #securityscare ;) The JollaStore RPM packages are somewhat safer, but only because they are manually/statically analyzed. Just an example of why I think "security scares" are bad. People tend to misplace their fears... |
All times are GMT. The time now is 09:39. |
vBulletin® Version 3.8.8