Bash Code Injection Vulnerability via Specially Crafted Environment Variables

Amit Nepal amit at amitnepal.com
Thu Sep 25 09:11:25 MST 2014


A critical vulnerability in the Bourne again shell, simply known as Bash 
and which is present in most Linux and UNIX distributions and Apple’s 
Mac OS X, has been discovered and administrators are being urged to 
patch immediately.

The flaw allows an attacker to remotely attach a malicious executable to 
a variable that is executed when Bash is invoked.

- See more at: 
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x#sthash.QWca4NzP.dpuf
A critical vulnerability has been found in bash shell which allows an 
attacker to remotely attach a malicious variable to a variable that is 
executed when bash is invoked.

A critical vulnerability in the Bourne again shell, simply known as Bash 
and which is present in most Linux and UNIX distributions and Apple’s 
Mac OS X, has been discovered and administrators are being urged to 
patch immediately.

The flaw allows an attacker to remotely attach a malicious executable to 
a variable that is executed when Bash is invoked.

- See more at: 
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x#sthash.QWca4NzP.dpuf

A critical vulnerability in the Bourne again shell, simply known as Bash 
and which is present in most Linux and UNIX distributions and Apple’s 
Mac OS X, has been discovered and administrators are being urged to 
patch immediately.

The flaw allows an attacker to remotely attach a malicious executable to 
a variable that is executed when Bash is invoked.

- See more at: 
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x#sthash.QWca4NzP.dpuf

A critical vulnerability in the Bourne again shell, simply known as Bash 
and which is present in most Linux and UNIX distributions and Apple’s 
Mac OS X, has been discovered and administrators are being urged to 
patch immediately.

The flaw allows an attacker to remotely attach a malicious executable to 
a variable that is executed when Bash is invoked.

- See more at: 
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x#sthash.QWca4NzP.dpuf 


A critical vulnerability in the Bourne again shell, simply known as Bash 
and which is present in most Linux and UNIX distributions and Apple’s 
Mac OS X, has been discovered and administrators are being urged to 
patch immediately.

The flaw allows an attacker to remotely attach a malicious executable to 
a variable that is executed when Bash is invoked.

- See more at: 
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x#sthash.QWca4NzP.dpuf
http://threatpost.com/major-bash-vulnerability-affects-linux-unix-mac-os-x
http://seclists.org/oss-sec/2014/q3/650
https://access.redhat.com/articles/1200223



*Amit K Nepal
Chief Information Officer
(RHCE, CCENT, C|EH, C|HFI, GIAC ISO 27000 Specialist)
omNovia Technologies Inc. *

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.phxlinux.org/pipermail/plug-discuss/attachments/20140925/76b0cf6a/attachment.html>


More information about the PLUG-discuss mailing list