kdryer39 sends this news from CSO: A remotely exploitable vulnerability has been discovered by Stephane Chazelas in bash on Linux, and it is unpleasant. The vulnerability has the CVE identifier CVE-2014-6271. This affects Debian as well as other Linux distributions. The major attack vectors that have been identified in this case are HTTP requests and CGI scripts. Another attack surface is OpenSSH through the use of AcceptEnv variables. Also through TERM and SSH_ORIGINAL_COMMAND. An environmental variable with an arbitrary name can carry a nefarious function which can enable network exploitation.
from Slashdot http://ift.tt/1mTo9Y2
via http://ift.tt/1mTo9Y2
Read more of this story at Slashdot.
from Slashdot http://ift.tt/1mTo9Y2
via http://ift.tt/1mTo9Y2
Blogger Comment