bk99.de entertain the web since 1997

Shellshock executes commands via Bash environment variables

Summary

Stephane Chazelas reports a Bash hole in which data after exported function definitions is executed as commands. The hole was assigned CVE-2014-6271. It affected numerous historical Bash versions.

Ideas

  • Bash imported functions from specially formatted environment variables.
  • Appended text was unexpectedly executed during the import.
  • CGI passed remote headers into the process environment.
  • Numerous network services started Bash indirectly.

Insights

  • Harmless data becomes dangerous as soon as a parser treats it as code.
  • Old convenience features can carry hidden attack surfaces for decades.
  • An inventory of indirect dependencies determines how fast you can respond.

Facts

  • The first patches did not eliminate all variants.

Recommendations

  • Update Bash and restart affected services.
  • Look for CGI and DHCP paths with shell calls.

References

Read the original article

Search the Web Archive