Войти в систему

Home
    - Создать дневник
    - Написать в дневник
       - Подробный режим

LJ.Rossia.org
    - Новости сайта
    - Общие настройки
    - Sitemap
    - Оплата
    - ljr-fif

Редактировать...
    - Настройки
    - Список друзей
    - Дневник
    - Картинки
    - Пароль
    - Вид дневника

Сообщества

Настроить S2

Помощь
    - Забыли пароль?
    - FAQ
    - Тех. поддержка



Пишет LWN.net ([info]syn_lwnheadline)
@ 2014-10-02 15:21:00


Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Zalewski on the other bash RCEs (CVE-2014-6277 and CVE-2014-6278)
Those interested in the more recently discovered bash vulnerabilities will
likely want to have a look at this detailed posting from Michal Zalewski.
Then make sure your systems are updated. "I initially shared the findings privately with vendors, but because of
the intense scrutiny that this codebase is under, the ease of
reproducing these results with an open-source fuzzer, and the
now-broad availability of upstream mitigations, there seems to be
relatively little value in continued secrecy.
"


(Читать комментарии) (Добавить комментарий)