bash: code execution
bash: code execution
Posted Oct 5, 2016 13:30 UTC (Wed) by nix (subscriber, #2304)Parent article: bash: code execution
Note: Chet pointed out that this is not $HOSTNAME; it is the result of gethostname(). An attacker who can set the HOSTNAME environment variable cannot exploit this, only someone who can force the system to set its hostname to $(bad stuff) can do so.
