5 ms·
This is an... odd submission. But I'm the guy who found this and the '78 one. To cut to the chase, run this command from within bash: _x='() { echo vulnerable;
by f- 12y ago
This is an... odd submission. But I'm the guy who found this and the '78 one. To cut to the chase, run this command from within bash:
_x='() { echo vulnerable; }' bash -c '_x 2>/dev/null || echo not vulnerable'
If it says "vulnerable", you need to:
1) Immediately update bash to the latest version provided by your distro, or manually recompile with all the applicable patches from ftp://ftp.gnu.org/gnu/bash/ (look at bash-*-patches for your version).
2) Make sure that you have a more reliable way to stay in the loop on important security updates in the future, since most major vulns don't make it to HN - and this one is more than a week old.
...
If you're interested in what "CVE-2014-6277" actually is, or what that test does, check out my recent blog posts, probably starting with:
http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-...