<div dir="ltr">Ars Technica is reporting that another patch is out now:<div><br></div><div><a href="http://arstechnica.com/security/2014/09/new-shellshock-patch-rushed-out-to-resolve-gaps-in-first-fix/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+arstechnica%2Findex+%28Ars+Technica+-+All+content%29">http://arstechnica.com/security/2014/09/new-shellshock-patch-rushed-out-to-resolve-gaps-in-first-fix/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+arstechnica%2Findex+%28Ars+Technica+-+All+content%29</a><br></div><div><br></div><div>Say what you want about Linux, the community is very fast to fix things!</div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 26 September 2014 15:14, William Park <span dir="ltr"><<a href="mailto:opengeometry@yahoo.ca" target="_blank">opengeometry@yahoo.ca</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Fri, Sep 26, 2014 at 11:27:55AM -0400, Giles Malet wrote:<br>
> On 14-09-25 07:18 PM, William Park wrote:<br>
> >If the command is built-in, then shell runs it.<br>
><br>
> We're getting somewhat off topic, but bash will start subshells for certain<br>
> loops. I can't remember off the top of my head which, but I know to be<br>
> carefully of variable assignment within a loop, since if it's done in a<br>
> subshell the assignment is lost.<br>
><br>
> Some thing like:<br>
><br>
> A="a"; loop ... A=b ... end loop; echo $A<br>
><br>
> produces "a", not "b", since that second assignment is lost.<br>
<br>
That would be if the loop is part of pipe, because each part is separate<br>
process, ie. fork/exec with consecutive parts connected to each other by<br>
pipe.<br>
<br>
><br>
> But it's true what people have said: because of all this your running shell<br>
> is probably pretty safe from being 0wned; subshells are vulnerable, unless<br>
> you have a new binary.<br>
><br>
> g<br>
><br>
><br>
> _______________________________________________<br>
> kwlug-disc mailing list<br>
> <a href="mailto:kwlug-disc@kwlug.org">kwlug-disc@kwlug.org</a><br>
> <a href="http://kwlug.org/mailman/listinfo/kwlug-disc_kwlug.org" target="_blank">http://kwlug.org/mailman/listinfo/kwlug-disc_kwlug.org</a><br>
<br>
<br>
_______________________________________________<br>
kwlug-disc mailing list<br>
<a href="mailto:kwlug-disc@kwlug.org">kwlug-disc@kwlug.org</a><br>
<a href="http://kwlug.org/mailman/listinfo/kwlug-disc_kwlug.org" target="_blank">http://kwlug.org/mailman/listinfo/kwlug-disc_kwlug.org</a><br>
</blockquote></div><br></div>