http://ftp.gnu.org/pub/gnu/bash/bash-4.3-patches/bash43-025 を少しみてみた。あまりちゃんと読んでいないので、参考程度に。 脆弱性の概要 seclistsの投稿によると、 Bash supports exporting not just shell variables, but also shell functions to other bash instances, via the process environment to (indirect) child processes. Current bash versions use an environment variable named by the function name, and a function definition starting with “() {” i