Publish a security note about bash "shellshock" vulnerability

Bug #1374055 reported by Nathan Kinder
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Security Notes
Fix Released
High
Tim Kelsey

Bug Description

We should publish a generic OSSN about the recently announced bash "shellshock" vulnerability. We have not found any evidence of incorrect shell usage in OpenStack yet, but this seems like an important enough issue that we should raise awareness by publishing a OSSN (similar to what we did for heartbleed).

Tim Kelsey (tim-kelsey)
Changed in ossn:
assignee: nobody → Tim Kelsey (tim-kelsey)
status: New → In Progress
Revision history for this message
Nathan Kinder (nkinder) wrote :

This was published as OSSN-0030:

  https://wiki.openstack.org/wiki/OSSN/OSSN-0030

Changed in ossn:
status: In Progress → Fix Released
Changed in ossn:
importance: Undecided → High
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers