Bash vulnerability - the original fix for this issue was incorrect

by George Chetcuti [Published on 26 Sept. 2014 / Last Updated on 26 Sept. 2014]

The original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

GNU Bash vulnerability allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock."

However, on Ubuntu Systems the problem can be corrected by updating your system with the latest package version. In general, a standard system update will make all the necessary changes.

Read more about how to update Ubuntu here - http://www.ubuntu.com/usn/usn-2362-1/

See Also


Review and Comments

* Required field

See Also

Featured Links