Further flaws in Bash Require Further More Patching
Google security researcher Michael 'lcamtuf' Zalewski says he's discovered a new remote code execution vulnerability in the Bash parser (CVE-2014-6278)
that is essentially equivalent to the original Shellshock bug, and
trival to exploit. "The first one likely permits remote code execution,
but the attack would require a degree of expertise to carry out,"
Zalewski said. "The second one is essentially equivalent to the original
flaw, trivially allowing remote code execution even on systems that
deployed the fix for the initial bug," he added.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.