Shellshock executes commands via Bash environment variables
Summary
Stephane Chazelas reports a Bash hole in which data after exported function definitions is executed as commands. The hole was assigned CVE-2014-6271. It affected numerous historical Bash versions.
Ideas
- Bash imported functions from specially formatted environment variables.
- Appended text was unexpectedly executed during the import.
- CGI passed remote headers into the process environment.
- Numerous network services started Bash indirectly.
Insights
- Harmless data becomes dangerous as soon as a parser treats it as code.
- Old convenience features can carry hidden attack surfaces for decades.
- An inventory of indirect dependencies determines how fast you can respond.
Facts
- The first patches did not eliminate all variants.
Recommendations
- Update Bash and restart affected services.
- Look for CGI and DHCP paths with shell calls.
References
Links to the original source and the Web Archive open in a new tab.