09-25-2014, 05:46 AM 
		
	
	
		I just ran the commands on LL2
 
env X="() { :;} ; echo busted" /bin/sh -c "echo stuff"
env X="() { :;} ; echo busted" bash -c "echo stuff"
and the second command came back with "busted"
Meaning LL is vulnerable
I imagine the patch for this is reliant on Ubuntu developers?
	
	
	
env X="() { :;} ; echo busted" /bin/sh -c "echo stuff"
env X="() { :;} ; echo busted" bash -c "echo stuff"
and the second command came back with "busted"
Meaning LL is vulnerable
I imagine the patch for this is reliant on Ubuntu developers?
I'm just this guy ... Y'know!?
Registered Linux User 533331
	
	
Registered Linux User 533331

 
 

 


![[Image: X5qGkCg.png]](https://imgur.com/X5qGkCg.png)
![[Image: 0op1GNe.png]](https://i.imgur.com/0op1GNe.png)
![[Image: LgJ2mtP.png]](https://i.imgur.com/LgJ2mtP.png)
![[Image: vLZcFUE.png]](https://imgur.com/vLZcFUE.png)
![[Image: lrUHro3.jpg]](https://i.imgur.com/lrUHro3.jpg)

![[Image: q7j1yAl.png]](http://i.imgur.com/q7j1yAl.png) 
 I have left the greater-than sign in there next to the version number so there is no need to change it in the future.
 I have left the greater-than sign in there next to the version number so there is no need to change it in the future.
	


![[Image: EtYqOrS.png%5D]](http://i.imgur.com/EtYqOrS.png%5D)