Toutes les vulnérabilités
CRITICALInfraexploited in the wild

CVE-2014-6271

Linux · GNU Bash

Résumé

GNU Bash mishandles trailing strings after function definitions stored in environment variables, executing them as commands when the variable is imported. Any service that passes attacker-controlled data into environment variables before invoking Bash, such as Apache CGI scripts, OpenSSH ForceCommand, or DHCP clients, can be tricked into running arbitrary commands remotely. Within hours of disclosure, botnets were mass-scanning and exploiting unpatched systems. The trivial exploitability and the ubiquity of Bash across Unix, Linux, and embedded devices made it one of the most severe vulnerabilities of its era.

Références

Vulnérabilités liées

Tout Infra →