The U.S. Department of Homeland Security’s Computer Emergency Readiness Team (US-CERT) issued a warning that Unix-based operating systems, including Linux, as well as Apple’s Mac OS X may be at risk.

According to cybersecurity company Trail of Bits, Heartbleed could allow personal information such as passwords and credit-card details to be stolen, but unlike Bash it could not be used to take over a system.

Source: Critical Bug in Unix Shell Bash Could Allow System Takeover | Money News | Latest Economic News | Reuters.

This is a really bad one. CGI in particular requires caution.

Rumor has it that zsh is also affected, so you should immediately inspect the contents of any scripts that invoke a shell…

For more details, I recommend this blog post → The Bash Vulnerability Is Extremely Serious.

It says:

Because CGI stores parameters in environment variables (*2), modifying an HTTP request header to contain

User-Agent: () { :; }; rm -rf /

might give you chills. I have not tested it myself, however.

Source: The Bash Vulnerability Is Extremely Serious

 

This is terrifying.

Incidentally, removing Bash as a countermeasure is apparently called “tooth extraction” in Japanese, a pun on the identical pronunciation of the words for removing Bash and extracting a tooth. Clever.

Reference Materials

Related posts

The XARA Vulnerabilities in MacOS X and iOS

This afternoon (June 18), GigaZine published a sensational article titled “Vulnerability Found That Allows iCloud, Email, and Browser-Saved Passwords to Be Stolen on iOS and OS…

OAuth · 2015-06-19