GNU Bourne-Again Shell (Bash) 'Shellshock' Vulnerability

Disclosed: 2014-10-01 00:00:00 By stephane-chazelas To ibb
Unknown
Vulnerability Details
GNU Bash versions 1.14 through 4.3 contain a flaw that processes commands placed after function definitions in the added environment variable, allowing remote attackers to execute arbitrary code via a crafted environment which enables network-based exploitation. Original disclosure: http://www.openwall.com/lists/oss-security/2014/09/24/11 Detailed analysis by lcamtuf: - http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html - http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html
Actions
View on HackerOne
Report Stats
  • Report ID: 29839
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report