Let me fix that for you.
hobbes@metalbaby:~$ export badvar='() { (a)=>\'
hobbes@metalbaby:~$ bash -c "somestring executeMe"
bash: badvar: line 1: syntax error near unexpected token `='
bash: badvar: line 1: `'
bash: error importing function definition for `badvar'
bash: executeMe: command not found
hobbes@metalbaby:~$ cat somestring #it exists but is empty.
hobbes@metalbaby:~$ bash -c "somestring date"
bash: badvar: line 1: syntax error near unexpected token `='
bash: badvar: line 1: `'
bash: error importing function definition for `badvar'
hobbes@metalbaby:~$ cat somestring
Thu Sep 25 11:01:35 CDT 2014
hobbes@metalbaby:~$ bash -c "somestring echo hello"
bash: badvar: line 1: syntax error near unexpected token `='
bash: badvar: line 1: `'
bash: error importing function definition for `badvar'
hobbes@metalbaby:~$ cat somestring
hello
Gititgotitgood? Great. Now how the heck does anybody think that is as bad as the first one?For this one, an attacker needs to control both the environment AND the command line of the child shell.
People, if those criteria are met, the attacker wins, with or without bugs.
Yes, yes, there are situations where the attacker has partial control of the command line via a filename argument or whatever--whatever indeed! That's not even in the same category as the first bug.