1 |
On Sun, 10 Mar 2013 15:26:29 +0000 |
2 |
Ciaran McCreesh <ciaran.mccreesh@××××××××××.com> wrote: |
3 |
|
4 |
> On Sun, 10 Mar 2013 14:48:06 +0100 |
5 |
> Michał Górny <mgorny@g.o> wrote: |
6 |
> > Well, unless we're talking about a theoretical package mangler which |
7 |
> > intentionally uses internal, old version of bash to prove the point. |
8 |
> |
9 |
> That's a good idea, maybe we'll do that. Sounds like a good way of |
10 |
> doing better input validation. Perhaps we could patch our internal bash |
11 |
> to make it easier to catch certain other errors too. |
12 |
|
13 |
Please don't forget to bundle a few rootkits inside, so your users |
14 |
won't have to wait for security issues to be found in the ye ol' bash |
15 |
version you'll use. |
16 |
|
17 |
-- |
18 |
Best regards, |
19 |
Michał Górny |