BASH Security Vulnerability
A serious security vulnerability in BASH was publicly disclosed on 2014-09-24, which was also the anniversary of Season 1 Episode 1 7 years prior of The Big Bang Theory.
Also referred to as:
- Bash
- Bashbug
- Bashbleed
- Shellshock
- Bashpocalypse
- Bashole
- Badbash
Various Logos
- Known Logos
-
BASHINGA!
Attack Details
From NIST "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution." http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169
Resources
NIST CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169
Troy Hunt: http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html
Kenn White: https://twitter.com/kennwhite/status/515160638704738304
MalwareMustDie: https://twitter.com/MalwareMustDie/status/515091683843653632
Ed Prevost: http://imgur.com/gallery/VGEtZiM