Bash security vulnerabilities-through specially crafted environment variable injection vulnerabilities
Bash security vulnerabilities-through specially crafted environment variable injection vulnerabilities
2014-09-25, in the morning, I saw a security breach in bash on the group and on Red Hat's website, so we should upgrade the version of bash as soon as possible.
New version: make sure that you are not allowed to execute a bash function after the end of the command.
Test vulnerabilities:
[root@ ~] # env Xbox'() {:;}; echo vulnerable' bash-c "echo this is a test"
Vulnerable
This is a test
If the above problem occurs, the new bash needs to be updated.
Update bash:
Yum update bash-y
Test for vulnerabilities:
[root@ ~] # env Xbox'() {:;}; echo vulnerable' bash-c "echo this is a test"
Bash: warning: x: ignoring function definition attempt
Bash: error importing function definition for `x'
This is a test
If shown above, the vulnerability has been fixed.
Currently, using bash's multithreaded script, 100 + servers have been updated.