[FFML] [ADMIN] Public statement on security issue CVE-2014-6271 aka Shellshock
Dennis Carr
dennisthetiger at chez-vrolet.net
Fri Sep 26 15:08:55 PDT 2014
Heya.
So I won't take up much with this, but here's the skinny.
First and foremost, yes, the exploit did apply to chez-vrolet.net, and, in
fact, anything that could be reached through bash would have been
vulnerable - including the list.
That said, as near as I can tell, no exploits have been made on this
server. An update was already available for Debian, and was picked up
before 09:00 PDT when a coworker mentioned "CVE" and "bash" in the same
sentence - which, aside from being a hallmark to a bad day coming where I
work, was my only warning that this was a thing.
So, in short, if there is a question as to whether all is well here at
Chez Vrolet Secret Labs, the answer is "yeah, as near as we can tell".
-Dennis
More information about the ffml
mailing list