"ShellShock" - what are you doing?
Mike Kerner
MikeKerner at roadrunner.com
Sat Sep 27 23:11:24 EDT 2014
Now we're working on round 3, by the way. There are some more things that
are coming out from fuzzing the parser. We'll see what the short and
medium-term plans are, but if I read it right, there are probably 3-5 more
patches, minimum, coming.
On Sat, Sep 27, 2014 at 11:04 PM, J. Landman Gay <jacque at hyperactivesw.com>
wrote:
> On 9/27/2014, 4:58 PM, Bruce Pokras wrote:
>
>> Some of the articles about the vulnerability make it sound like every
>> Mac on the planet could be taken over by bad guys. Talk about
>> spreading FUD!
>>
>
> Yeah. I think a lot of servers will be in trouble, but fewer consumers
> than the media makes it out to be. I have discovered:
>
> Android doesn't use a shell at all.
> iOS probably doesn't use a shell (but the article wasn't certain.)
> OS X isn't affected unless you're running a web server.
> Windows isn't affected.
> Most routers don't use bash because it is too large to fit into their
> relatively small amount of flash memory. (D-Link has a statement saying
> none of their routers use bash.)
>
> So it seems to me that Apache servers and 'nix users need updating but
> other consumers are for the most part okay, including mobile users.
>
> --
> Jacqueline Landman Gay | jacque at hyperactivesw.com
> HyperActive Software | http://www.hyperactivesw.com
>
>
> _______________________________________________
> use-livecode mailing list
> use-livecode at lists.runrev.com
> Please visit this url to subscribe, unsubscribe and manage your
> subscription preferences:
> http://lists.runrev.com/mailman/listinfo/use-livecode
>
--
On the first day, God created the heavens and the Earth
On the second day, God created the oceans.
On the third day, God put the animals on hold for a few hours,
and did a little diving.
And God said, "This is good."
More information about the use-livecode
mailing list