EDIT: I tested on CentOS 6.5 and Fedora 18 (for which we'd manually backported the Fedora 19 patches).
EDIT: I tested on CentOS 6.5 and Fedora 18 (for which we'd manually backported the Fedora 19 patches).
env ls='() { echo vulnerable; }' bash -c ls
on my recently patched CentOS box. If I'm reading that right, if I was vulnerable, I'd get the output 'vulnerable'? But, instead, I got the correct output of the `ls` command.
The linked article was pertinent because RedHat did patch bash in a different way than upstream. Here's the relevant quote:
> Our patch addresses the CVE-2014-7169 issue in a much better way than the upstream patch, we wanted to make sure the issue was properly dealt with.
That help?
And the post below which shows the contents of the RH patches should help, if I knew how to read it. :)
But... it seems to me that if this doesn't work:
env ls='() { echo vulnerable; }' bash -c ls
...then some scripts are now broken. Sorry, I don't know which ones. Needless to say, most bash scripts in existence don't take input from the wild wire. A sad day for those innocuous scripts.http://pkgs.fedoraproject.org/cgit/bash.git/commit/?id=6319f...
$ env 'BASH_FUNC_ls()=() { echo myls; }' bash -c ls
myls
But as others mention, this is not really a bash issue anymore, rather a general problem of sanitizing environments.