Security Portal

Intrusion Prevention Service

 
Signature Version: 4.990

 



WEB GNU Bash Remote Code Execution -6 (CVE-2014-6271, Shellshock)
 
Threat Level: Critical
Release Date: 2014/9/26
 
Category: Access Control
Signature ID: 1130029
Included In:
Affected OS: Linux, FreeBSD, Solaris, Other Unix, Mac OS
 
Description: A remote code execution vulnerability has been reported in GNU Bash. The vulnerability is due to insufficient validation of environment variables.
 
Impact: Remote code execution
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
Reference(s): CVE-2014-6271; msf; CVE-2014-7169; CVE-2014-7169; CVE-2014-7186; CVE-2014-7187; CVE-2014-6277; CVE-2014-6278
 

Search the Threat Database
Enter Rule ID or Name