Slashdot Mirror


Bash To Require Further Patching, As More Shellshock Holes Found

Bismillah writes Google security researcher Michael 'lcamtuf' Zalewski says he's discovered a new remote code execution vulnerability in the Bash parser (CVE-2014-6278) that is essentially equivalent to the original Shellshock bug, and trival to exploit. "The first one likely permits remote code execution, but the attack would require a degree of expertise to carry out," Zalewski said. "The second one is essentially equivalent to the original flaw, trivially allowing remote code execution even on systems that deployed the fix for the initial bug," he added.

7 of 329 comments (clear)

  1. More bugs and exploits by GeekWithAKnife · · Score: 5, Funny


    Rejoice my brethren; finally linux is becoming popular, the year of the desktop is upon us!

    --
    A 'singular oddity' is an event that cannot be explained and only happens when you are alone.
  2. Re:Soon to be patched by indeterminator · · Score: 4, Funny

    Nobody ever got fired for using Microsoft..

    Seems like a management oversight. I would be shocked to find that I have to pay for upgrades every couple of years.

  3. Re:There are no "remote" exploits for bash by Anonymous Coward · · Score: 5, Funny

    Anyone can stand up a rouge DHCP server on most networks.

    I tried to set up a rouge DHCP server once, but it left me marooned.

  4. Re:Soon to be patched by K.+S.+Kyosuke · · Score: 3, Funny

    Apparently, it is not "Ubuntu" but rather "Anonymous Coward" that actually means "I can't configure Debian".

    --
    Ezekiel 23:20
  5. Richard Stallman protests the name Shellshock by Anonymous Coward · · Score: 4, Funny

    You'd better call it the GNU/Shellshock security vulnerability!

  6. Re:Soon to be patched by NatasRevol · · Score: 5, Funny

    The reason Windows doesn't have problems like this

    HOLY

    FUCKING

    SHIT

    --
    There are two types of people in the world: Those who crave closure
  7. Re:Nothing to do with language by Anonymous Coward · · Score: 5, Funny

    The problem with bash is that even more than most shells (perhaps except for zsh), it's exceedingly obscure and baroque.

    Of course it is baroque. That's why they are working hard to fix it.