Shellshock (software bug): Difference between revisions

Content deleted Content added
m Qwertyus moved page ShellShock to Shellshock (software bug): no StudlyCaps in sources
name not given by RH; intro for the general public
Line 1:
{{current event|date=September 2014}}
A'''Shellshock''' is the name of a serious security vulnerability in [[Bash (Unix shell)|BASH]], wasa publiclycommand disclosedinterpreter onused 24by Septembermany 2014[[web server]]s running [[Apache HTTP Server|Apache]] and/or [[Secure Shell|SSH]]. The vulnerability, whichwas haspublicly beendisclosed namedon ''Shellshock''24 bySeptember its2014 discoverer,by Huzaifa Sidhpurwala of [[Red Hat]].<ref>{{Cite web
| author = Huzaifa Sidhpurwala
| title = Bash specially-crafted environment variables code injection attack
Line 6:
| url = https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/
| date = 2014-09-24
}}</ref>
}}</ref>It has been added to the United States [[National Vulnerability Database]] with identifier CVE-2014-7169.<ref name=NIST>
{{cite web
|url=http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169