GNU Bash CVE-2014-6278 Incomplete Fix Remote Code Execution Vulnerability
BID:70166
Info
GNU Bash CVE-2014-6278 Incomplete Fix Remote Code Execution Vulnerability
| Bugtraq ID: | 70166 |
| Class: | Design Error |
| CVE: |
CVE-2014-6278 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2014 12:00AM |
| Updated: | Jul 05 2016 09:53PM |
| Credit: | Michal Zalewski |
| Vulnerable: |
Xerox WorkCentre 7245 Xerox WorkCentre 7242 Xerox WorkCentre 7238 Xerox WorkCentre 7235 Xerox WorkCentre 7232 Xerox WorkCentre 7228 Xerox Phaser 7800 0 Xerox Phaser 6700 0 Xerox ColorQube 9393 Xerox ColorQube 9303 Xerox ColorQube 9302 Xerox ColorQube 9301 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Sun Solaris 11 Oracle VM VirtualBox 3.2 Oracle VM VirtualBox 3.1 Oracle Linux 5 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 McAfee Email Gateway 7.0 Patch 1 McAfee Email Gateway 7.0 McAfee Email Gateway 6.7.2 Hotfix 2 McAfee Email Gateway 6.7.2 Hotfix 1 IBM DS8000 0 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 HP Insight Control 0 GNU GNU bash 4.2 Gentoo Linux Cisco Wide Area Application Services (WAAS) 0 Cisco Unified IP Phone 0 Cisco Unified Contact Center Express 0 Cisco Network Analysis Module 0 Cisco MDS 0 Cisco GSS 4492R Global Site Selector 0 Cisco Emergency Responder 1.1 Cisco Digital Media Manager (DMM) 5.0 Cisco Digital Media Manager 0 Cisco Cisco Show and Share 5(2) Avaya 96x1 IP Deskphone 6.2 Avaya 96x1 IP Deskphone 6 |
| Not Vulnerable: | |
Discussion
GNU Bash CVE-2014-6278 Incomplete Fix Remote Code Execution Vulnerability
GNU Bash is prone to remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Note: This issue exists due to an incomplete fix for CVE-2014-6271 and CVE-2014-7169.(identified in BID 70103 - GNU Bash CVE-2014-6271 Remote Code Execution Vulnerability and BID 70137 - GNU Bash CVE-2014-7169 Incomplete Fix Remote Code Execution Vulnerability respectively).
GNU Bash is prone to remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Note: This issue exists due to an incomplete fix for CVE-2014-6271 and CVE-2014-7169.(identified in BID 70103 - GNU Bash CVE-2014-6271 Remote Code Execution Vulnerability and BID 70137 - GNU Bash CVE-2014-7169 Incomplete Fix Remote Code Execution Vulnerability respectively).
Solution / Fix
GNU Bash CVE-2014-6278 Incomplete Fix Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Bash CVE-2014-6278 Incomplete Fix Remote Code Execution Vulnerability
References:
References:
- Bash bug: apply Florian's patch now (CVE-2014-6277 and CVE-2014-6278) (lcamtuf's blog)
- BASH Homepage (GNU)
- Bash-4.3 Official Patch 30 (Chet Ramey)
- Check Point Response to CVE-2014-6271 and CVE-2014-7169 Bash Code Injection vuln (Check Point)
- IBM Real-time Compression Appliance is exposed to the following Bash vulnerabili (IBM)
- MOVE Security Update for CVE-2014-6271 Bash / Shellshock Code Injection Exploit (McAfee)
- Multiple vulnerabilities in Bash (Oracle)
- Quick notes about the bash bug, its impact, and the fixes so far (lcamtuf's blog)
- Remote Exploit Vulnerability in Bash - (Shellshock) (Fortinet)
- Security Bulletin: Vulnerabilities in Bash affect certain Qlogic products that I (IBM)
- Security Notice-Bash Code Injection Vulnerability (Huawei)
- SOL15629: GNU Bash vulnerabilities CVE-2014-6271 and CVE-2014-7169 (F5 Networks)
- Vulnerabilities in Bash affect IBM FlashSystem 840 and V840 (IBM)
- Vulnerabilities in Bash affect IBM Netezza Host Management (IBM)
- Vulnerabilities in Bash affect IBM PureApplication System (IBM)
- Vulnerabilities in Bash affect IBM SDN VE (IBM)
- Vulnerabilities in Bash affect IBM Smart Analytics System 5600 (IBM)
- Vulnerabilities in Bash affect IBM Smart Analytics System 7600, 7700 and 7710 (IBM)
- Vulnerabilities in Bash affect IBM SONAS (IBM)
- Vulnerabilities in Bash affect IBM System Storage Storwize V7000 Unified (IBM)
- Vulnerabilities in Bash affect IBM Workload DeployerVulnerabilities in Bash affe (IBM)
- Vulnerabilities in Bash affect ProtecTIER (IBM)
- Vulnerabilities in Bash affect SAN Volume Controller and Storwize Family (IBM)
- Vulnerabilities in Bash affect the IBM Hyper-Scale Manager component of the XIV (IBM)
- Vulnerabilities in Bash affect Virtual Server Protection for VMware (IBM)
- [security bulletin] HPSBMU03165 rev.1 - HP Propel running Bash Shell, Remote Co (HP)
- CA20141001-01: Security Notice for Bash Shellshock Vulnerability (SecLists.Org)
- 2014-09 Out of Cycle Security Bulletin: Multiple Products: Shell Command Injecti (Juniper Networks)
- 2014-11 Security Bulletin: Network and Security Manager NSM Appliances: Multiple (Juniper)
- Avaya Audiocodes Gateways Response to GNU Bash (shellshock) Vulnerabilities (CVE (Avaya)
- Bash Command Injection Vulnerability (Supplement) (CERT)
- Bash Vulnerabilities - CVE-2014-7169 (Oracle)
- Check Point Software Technologies Information for VU#252743 GNU Bash shell execu (KB CERT)
- GNU Bash Environmental Variable Command Injection Vulnerability (Cisco)
- HP Automation Insight running Bash Shell Remote Code Execution (HP)
- HP Business Service Automation Essentials running Bash Shell, Remote Code Execut (HP)
- HP Integrity SD2 CB900s i4 & i2 Server running Bash Shell Remote Code Execution (HP)
- HP Integrity Superdome X and HP Converged System 900 for SAP HANA (HP)
- HP Operation Agent Virtual Appliance, Bash Shell, Remote Code Execution (HP)
- HP Operations Analytics running Bash Shell, Remote Code Execution (HP)
- HP StoreAll Operating System Software running Bash Shell, Remote Code Execution (HP)
- HP StoreEver ESL E-series Tape Library and HP Virtual Library System (VLS) runni (HP)
- HP StoreFabric B-series switches running Bash Shell, Remote Code Execution (HP)
- HP Virtualization Performance Viewer, Bash Shell, Remote Code Execution (HP)
- HPSBGN03233 rev.1 - HP OneView running OpenSSL, Remote Denial of Service (DoS), (HP)
- HPSBGN03250 rev.1 - HP Cloudsystem Foundation and HP CloudSystem Enterprise Soft (HP)
- HPSBHF03124 rev.1 - HP Thin Clients running Bash, Remote Execution of Code (HP)
- HPSBHF03125 rev.1 - HP Next Generation Firewall (NGFW) running Bash Shell, Remot (HP)
- HPSBMU03182 rev.1 - HP Server Automation running Bash Shell RCE (HP)
- HPSBMU03217 rev.1 - HP Vertica Analytics Platform running Bash Shell RCE (HP)
- HPSBMU03245 rev.1 (Seclist)
- HPSBMU03246 rev.1 (HP)
- HPSBMU03246 rev.1 (Seclist)
- HPSBST03154 rev.1 - HP StoreFabric C-series MDS switches and HP C-series Nexus 5 (HP)
- HPSBST03155 rev.1 - HP StoreFabric H-series switches running Bash Shell, Remote (HP)
- HPSBST03181 rev.1 - HP StoreEver ESL G3 Tape Library running Bash Shell, Remote (HP)
- IBM Corporation Information for VU#252743 GNU Bash shell executes commands in ex (KB CERT)
- Juniper Networks, Inc. Information for VU#252743 (KB CERT)
- McAfee Security Bulletin - Bash Shellshock Code Injection Exploit Updates for CV (McAfee)
- Mini Bulletin XRX 15K WorkCentre 77 xx Series R15 - 03 SPAR Release 061.090.225 (Xerox)
- Mini Bulletin XRX 15M WorkCentre 75 xx Series SPAR Release 061. 121 .225 . 0 6 1 (Xerox)
- Mini Bulletin XRX1 5 H Phaser 78 00 R14 - 12 SPAR Release Release 08 1. 150 . 1 (Xerox)
- Mini Bulletin XRX1 5E WorkCentre 57xx Series Release 061.132.224. 35203 (Xerox)
- Mini Bulletin XRX1 5G Phaser 6700 R14 - 12 SPAR Release R elease 08 1. 140 . 105 (Xerox)
- Mini Bulletin XRX14G WorkCentre 77xx Series R14-10 SPAR Release 061.090.224.3030 (Xerox)
- Mini Bulletin XRX14H (Xerox)
- Mini Bulletin XRX15F (Xerox)
- Security Advisory-Bash Code Injection Vulnerability (Huawei)
- Security Bulletin: UPDATE: Vulnerabilities in Bash affect AIX Toolbox for Linux (IBM)
- Security Bulletin: Vulnerabilities in Bash affect certain IBM N Series products (IBM)
- Security Bulletin: Vulnerabilities in Bash affect DS8000 HMC (CVE-2014-6271, CVE (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Algo Risk Service on Cloud (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM eDiscovery Identification (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Flex System 40Gb Ethernet/ (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Flex System Manager (FSM): (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM InfoSphere Balanced Wareho (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM InfoSphere Guardium Databa (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM PureData System for Operat (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM PureData System for Transa (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Security Access Manager fo (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Security Access Manager fo (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM SmartCloud Entry Appliance (IBM)
- Security Bulletin: Vulnerabilities in Bash affect IBM Worklight Quality Assuranc (IBM)
- Security Bulletin: Vulnerabilities in Bash affect Network Intrusion Prevention S (IBM)
- Security Bulletin: Vulnerabilities in Bash affect Power Hardware Management Cons (IBM)
- Security Bulletin: Vulnerabilities in Bash affect Proventia Network Enterprise S (IBM)
- Security Bulletin: Vulnerabilities in Bash affect QRadar SIEM, QRadar Vulnerabil (IBM)
- Security Bulletin: Vulnerabilities in Bash affect TSSC (CVE-2014-6271, CVE-2014- (IBM)
- Security Bulletin: Vulnerabilities in Bash affect WebSphere Message Broker v8 HV (IBM)
- Security Bulletin: Vulnerabilities in Bash affects IBM Privileged Identity Manag (IBM)
- Security Bulletin: Vulnerabilities in Bash and GNU C Library affect WebSphere Tr (IBM)
- Security Bulletin: WebSphere Process Server Hypervisor Edition Bash vulnerabilit (IBM)
- Updated - Security Bulletin: Vulnerabilities in Bash affect IBM Algo One Managed (IBM)
- VMSA-2014-0010 VMware product updates address critical Bash security vulnerabili (VMware)
- Vulnerabilities in Bash affect IBM SAN b-type Switches (IBM)
- Vulnerabilities in Bash affect IBM System x servers (IBM)
- Vulnerabilities in Bash affect IBM/Cisco Switches and Directors (IBM)
- Wind River bash Security Update (Avaya)