[FFML] [ADMIN] Public statement on security issue CVE-2014-6271 aka Shellshock

Dennis Carr dennisthetiger at chez-vrolet.net
Fri Sep 26 15:08:55 PDT 2014


Heya.

So I won't take up much with this, but here's the skinny.

First and foremost, yes, the exploit did apply to chez-vrolet.net, and, in 
fact, anything that could be reached through bash would have been 
vulnerable - including the list.

That said, as near as I can tell, no exploits have been made on this 
server.  An update was already available for Debian, and was picked up 
before 09:00 PDT when a coworker mentioned "CVE" and "bash" in the same 
sentence - which, aside from being a hallmark to a bad day coming where I 
work, was my only warning that this was a thing.

So, in short, if there is a question as to whether all is well here at 
Chez Vrolet Secret Labs, the answer is "yeah, as near as we can tell".

-Dennis


More information about the ffml mailing list