How worse is the shellshock bash bug than Heartbleed?

Georgi Guninski guninski at guninski.com
Tue Sep 30 02:26:02 PDT 2014


Recently a bash(1) bug called shellsock died.
It affected Apache, DHCP, SSH,qmail,Pure-FTPd and other stuff.
Summary of affected: 
https://github.com/mubix/shellshocker-pocs/blob/master/README.md

I find this _much_ worse than the passive Heartbleed.

How worse is the shellshock bash bug than Heartbleed?




More information about the cypherpunks mailing list