[yocto] [PATCH] bash: update to latest (025) patchset (fixes CVE-2014-6271)

Burton, Ross ross.burton at intel.com
Thu Sep 25 15:40:39 PDT 2014


Hu Francesco,

On 25 September 2014 11:35, Francesco Del Degan <f.deldegan at endian.com> wrote:
> Updated to reflect the latest patchset in bash 4.3.
> Fixes the CVE-2014-6271.

I'm hearing that this isn't a complete fix, so lets wait for more patches.

Is it possible to cherry-pick just the security fixes, instead of
every patch they've released?

Finally, patches for oe-core should go to openembedded-core@, not yocto at .

Ross



More information about the yocto mailing list