GNU Bash ÇéÐαäÁ¿Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2014-6271) (Alert2014-08)
2014-09-25
ÐÎò£º
CVE ID£ºCVE-2014-6271ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
GNU Bash <= 4.3
×ÛÊö£º
======
GNU Bash£¨Bourne again shell£©ÀàËÆUNIXµÄshell£¬ÆÕ±éʹÓÃÔÚLinuxϵͳÄÚ£¬×î³õµÄ¹¦Ð§½öÊÇÒ»¸ö¼òÆÓµÄ»ùÓÚÖն˵ÄÏÂÁîÚ¹ÊÍÆ÷¡£
GNU Bash 4.3¼°Ö®Ç°°æ±¾ÔÚ´¦Öóͷ£Ä³Ð©½á¹¹µÄÇéÐαäÁ¿Ê±±£´æÇå¾²Îó²î£¬¿ÉÄÜÔÊÐí¹¥»÷ÕßÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£
Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±×°Öó§É̵IJ¹¶¡¾ÙÐÐÉý¼¶¡£
ÆÊÎö£º
======
GNU Bash 4.3¼°Ö®Ç°°æ±¾ÔÚ´¦Öóͷ£Ä³Ð©½á¹¹µÄÇéÐαäÁ¿Ê±±£´æÇå¾²Îó²î£¬ÏòÇéÐαäÁ¿ÖµÄڵĺ¯Êý½ç˵ºóÌí¼Ó¶àÓàµÄ×Ö·û´®»á´¥·¢´ËÎó²î£¬¹¥»÷Õß¿ÉʹÓôËÎó²î¸Ä±ä»òÈÆ¹ýÇéÐÎÏÞÖÆ£¬ÒÔÖ´ÐÐshellÏÂÁijЩ·þÎñºÍÓ¦ÓÃÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÌṩÇéÐαäÁ¿ÒÔʹÓôËÎó²î¡£´ËÎó²îÔ´ÓÚÔÚŲÓÃbash shell֮ǰ¿ÉÒÔÓýṹµÄÖµ½¨ÉèÇéÐαäÁ¿¡£ÕâЩ±äÁ¿¿ÉÒÔ°üÀ¨´úÂ룬ÔÚshell±»Å²Óúó»á±»Á¬Ã¦Ö´ÐС£
´ËÎó²î¿ÉÄÜ»áÓ°Ï쵽ʹÓÃForceCommand¹¦Ð§µÄOpenSSH sshd¡¢Ê¹ÓÃmod_cgi»òmod_cgidµÄApache·þÎñÆ÷¡¢DHCP¿Í»§¶Ë¡¢ÆäËûʹÓÃbash×÷ΪڹÊÍÆ÷µÄÓ¦Óõȡ£
ÏÖÔÚÒÔΪʹÓÃmod_php/mod_python/mod_perlµÄApache httpd²»ÊÜ´ËÎÊÌâÓ°Ïì¡£
²âÊÔÒªÁ죺
ÍâµØÑéÖ¤bashÊÇ·ñÊÜÓ°ÏìµÄÒªÁ죺$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test
ÈôÊÇÏÔʾÉÏÊöÐÅÏ¢£¬ÔòÊÜÓ°Ïì¡£
$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
bash: warning: x: ignoring function definition attempt
bash: error importing function definition for \`x'
ÈôÊÇÏÔʾÉÏÊöÐÅÏ¢£¬Ôò²»ÊÜÓ°Ïì¡£
³§ÉÌ״̬£º
==========
GNU
---
ÏÖÔÚ³§ÉÌÒѾÐû²¼ÁËÉý¼¶²¹¶¡ÒÔÐÞ¸´Õâ¸öÇå¾²ÎÊÌ⣬Çëµ½³§É̵ÄÖ÷Ò³ÏÂÔØ£º
http://www.gnu.org/software/bash
http://ftp.gnu.org/gnu/bash/
¸÷´óLinux¿¯ÐаæÒ²ÒѾÌṩÁËÏà¹Ø²¹¶¡£¬ÇëʵʱÉý¼¶¡£
¸½¼ÓÐÅÏ¢£º
==========
1. https://bugzilla.redhat.com/show_bug.cgi?id=1141597
2. https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/
3. https://bugzilla.redhat.com/attachment.cgi?id=938976
4. http://www.nsfocus.net/vulndb/27942

¾ÅÓÎÀϸçÔÆ





