Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-6271 | First vendor Publication | 2014-09-24 |
Vendor | Cve | Last vendor Modification | 2025-03-13 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('OS Command Injection') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:26521 | |||
Oval ID: | oval:org.mitre.oval:def:26521 | ||
Title: | RHSA-2014:1293: bash security update (Critical) | ||
Description: | The GNU Bourne Again shell (Bash) is a shell and command language interpreter compatible with the Bourne shell (sh). Bash is the default shell for Red Hat Enterprise Linux. A flaw was found in the way Bash evaluated certain specially crafted environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue. (CVE-2014-6271) For additional information on the CVE-2014-6271 flaw, refer to the Knowledgebase article at https://access.redhat.com/articles/1200223 Red Hat would like to thank Stephane Chazelas for reporting this issue. All bash users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:1293-00 CESA-2014:1293 CVE-2014-6271 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 7 CentOS Linux 5 CentOS Linux 6 CentOS Linux 7 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26539 | |||
Oval ID: | oval:org.mitre.oval:def:26539 | ||
Title: | USN-2362-1 -- bash vulnerability | ||
Description: | Bash allowed bypassing environment restrictions in certain environments. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2362-1 CVE-2014-6271 | Version: | 3 |
Platform(s): | Ubuntu 14.04 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26642 | |||
Oval ID: | oval:org.mitre.oval:def:26642 | ||
Title: | DSA-3032-1 bash - security update | ||
Description: | Stephane Chazelas discovered a vulnerability in bash, the GNU Bourne-Again Shell, related to how environment variables are processed. In many common configurations, this vulnerability is exploitable over the network, especially if bash has been configured as the system shell. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3032-1 CVE-2014-6271 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26665 | |||
Oval ID: | oval:org.mitre.oval:def:26665 | ||
Title: | DSA-3035-1 bash - security update | ||
Description: | Tavis Ormandy discovered that the patch applied to fix <a href="https://security-tracker.debian.org/tracker/CVE-2014-6271">CVE-2014-6271</a> released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was incomplete and could still allow some characters to be injected into another environment (<a href="https://security-tracker.debian.org/tracker/CVE-2014-7169">CVE-2014-7169</a>). With this update prefix and suffix for environment variable names which contain shell functions are added as hardening measure. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3035-1 CVE-2014-7169 CVE-2014-6271 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26685 | |||
Oval ID: | oval:org.mitre.oval:def:26685 | ||
Title: | ELSA-2014-1294 -- bash security update (Critical) | ||
Description: | The GNU Bourne Again shell (Bash) is a shell and command language interpreter compatible with the Bourne shell (sh). Bash is the default shell for Red Hat Enterprise Linux. A flaw was found in the way Bash evaluated certain specially crafted environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue. (CVE-2014-6271) For additional information on the CVE-2014-6271 flaw, refer to the Knowledgebase article at <A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223</A> Red Hat would like to thank Stephane Chazelas for reporting this issue. All bash users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2014-1294 CVE-2014-6271 | Version: | 3 |
Platform(s): | Oracle Linux 4 | Product(s): | bash |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:26764 | |||
Oval ID: | oval:org.mitre.oval:def:26764 | ||
Title: | Vulnerability affecting GNU Bash | ||
Description: | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2014-6271 | Version: | 4 |
Platform(s): | Sun Solaris 10 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26923 | |||
Oval ID: | oval:org.mitre.oval:def:26923 | ||
Title: | ELSA-2014-1293 -- bash security update (Critical) | ||
Description: | The GNU Bourne Again shell (Bash) is a shell and command language interpreter compatible with the Bourne shell (sh). Bash is the default shell for Red Hat Enterprise Linux. A flaw was found in the way Bash evaluated certain specially crafted environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue. (CVE-2014-6271) For additional information on the CVE-2014-6271 flaw, refer to the Knowledgebase article at <A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223</A> Red Hat would like to thank Stephane Chazelas for reporting this issue. All bash users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2014-1293 CVE-2014-6271 | Version: | 3 |
Platform(s): | Oracle Linux 6 Oracle Linux 7 Oracle Linux 5 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27118 | |||
Oval ID: | oval:org.mitre.oval:def:27118 | ||
Title: | ELSA-2014-1306 -- bash security update (Important) | ||
Description: | The GNU Bourne Again shell (Bash) is a shell and command language interpreter compatible with the Bourne shell (sh). Bash is the default shell for Red Hat Enterprise Linux. It was found that the fix for CVE-2014-6271 was incomplete, and Bash still allowed certain characters to be injected into other environments via specially crafted environment variables. An attacker could potentially use this flaw to override or bypass environment restrictions to execute shell commands. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue. (CVE-2014-7169) Applications which directly create bash functions as environment variables need to be made aware of changes to the way names are handled by this update. Note that certain services, screen sessions, and tmux sessions may need to be restarted, and affected interactive users may need to re-login. Installing these updated packages without restarting services will address the vulnerability, but functionality may be impacted until affected services are restarted. For more information see the Knowledgebase article at <A HREF="https://access.redhat.com/articles/1200223">https://access.redhat.com/articles/1200223</A> Note: Docker users are advised to use "yum update" within their containers, and to commit the resulting changes. For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the aforementioned Knowledgebase article. All bash users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2014-1306 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 CVE-2014-6271 | Version: | 3 |
Platform(s): | Oracle Linux 7 Oracle Linux 6 Oracle Linux 5 | Product(s): | bash |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27830 | |||
Oval ID: | oval:org.mitre.oval:def:27830 | ||
Title: | SUSE-SU-2014:1260-1 -- bash (critical) | ||
Description: | Bash was updated to fix unexpected code execution with environment variables (CVE-2014-6271). | ||
Family: | unix | Class: | patch |
Reference(s): | SUSE-SU-2014:1260-1 CVE-2014-6271 | Version: | 3 |
Platform(s): | SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Desktop 12 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28331 | |||
Oval ID: | oval:org.mitre.oval:def:28331 | ||
Title: | VMware product updates address critical Bash security vulnerabilities | ||
Description: | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2014-6271 | Version: | 4 |
Platform(s): | VMWare ESX Server 4.1 VMWare ESX Server 4.0 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Bash environment variable code injection over HTTP | More info here |
Bash Environment Variable Handling Shell Command Injection Via CUPS | More info here |
ShellShock DHCP Server | More info here |
ExploitDB Exploits
id | Description |
---|---|
2014-11-03 | PHP 5.x Shellshock Exploit (bypass disable_functions) |
2014-10-29 | CUPS Filter Bash Environment Variable Code Injection |
2014-10-04 | OpenVPN 2.2.29 - ShellShock Exploit |
2014-10-01 | IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injecti... |
2014-09-25 | GNU bash Environment Variable Command Injection (MSF) |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-09-25 | IAVM : 2014-A-0142 - GNU Bash Shell Code Execution Vulnerability Severity : Category I - VMSKEY : V0054753 |
Snort® IPS/IDS
Date | Description |
---|---|
2015-07-13 | Linux.Trojan.ChinaZ outbound connection RuleID : 34847 - Revision : 3 - Type : MALWARE-CNC |
2014-10-30 | Bash environment variable injection attempt RuleID : 32366-community - Revision : 2 - Type : OS-OTHER |
2014-12-02 | Bash environment variable injection attempt RuleID : 32366 - Revision : 2 - Type : OS-OTHER |
2014-10-24 | Bash CGI environment variable injection attempt RuleID : 32336-community - Revision : 2 - Type : OS-OTHER |
2014-11-25 | Bash CGI environment variable injection attempt RuleID : 32336 - Revision : 2 - Type : OS-OTHER |
2014-10-24 | Bash CGI environment variable injection attempt RuleID : 32335-community - Revision : 2 - Type : OS-OTHER |
2014-11-25 | Bash CGI environment variable injection attempt RuleID : 32335 - Revision : 2 - Type : OS-OTHER |
2014-10-03 | Bash environment variable injection attempt RuleID : 32069-community - Revision : 3 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32069 - Revision : 3 - Type : OS-OTHER |
2014-10-01 | Bash environment variable injection attempt RuleID : 32043-community - Revision : 3 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32043 - Revision : 3 - Type : OS-OTHER |
2014-10-01 | Bash environment variable injection attempt RuleID : 32042-community - Revision : 4 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32042 - Revision : 4 - Type : OS-OTHER |
2014-10-01 | Bash environment variable injection attempt RuleID : 32041-community - Revision : 4 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32041 - Revision : 4 - Type : OS-OTHER |
2014-10-01 | Bash environment variable injection attempt RuleID : 32039-community - Revision : 3 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32039 - Revision : 3 - Type : OS-OTHER |
2014-10-01 | Bash environment variable injection attempt RuleID : 32038-community - Revision : 3 - Type : OS-OTHER |
2014-11-16 | Bash environment variable injection attempt RuleID : 32038 - Revision : 3 - Type : OS-OTHER |
2014-09-25 | Malicious DHCP server bash environment variable injection attempt RuleID : 31985-community - Revision : 6 - Type : OS-OTHER |
2014-11-16 | Malicious DHCP server bash environment variable injection attempt RuleID : 31985 - Revision : 6 - Type : OS-OTHER |
2014-09-25 | Bash CGI environment variable injection attempt RuleID : 31978-community - Revision : 5 - Type : OS-OTHER |
2014-11-16 | Bash CGI environment variable injection attempt RuleID : 31978 - Revision : 5 - Type : OS-OTHER |
2014-09-25 | Bash CGI environment variable injection attempt RuleID : 31977-community - Revision : 5 - Type : OS-OTHER |
2014-11-16 | Bash CGI environment variable injection attempt RuleID : 31977 - Revision : 5 - Type : OS-OTHER |
2014-09-25 | Bash CGI environment variable injection attempt RuleID : 31976-community - Revision : 5 - Type : OS-OTHER |
2014-11-16 | Bash CGI environment variable injection attempt RuleID : 31976 - Revision : 5 - Type : OS-OTHER |
2014-09-25 | Bash CGI environment variable injection attempt RuleID : 31975-community - Revision : 6 - Type : OS-OTHER |
2014-11-16 | Bash CGI environment variable injection attempt RuleID : 31975 - Revision : 6 - Type : OS-OTHER |
Metasploit Database
id | Description |
---|---|
2014-09-29 | IPFire Bash Environment Variable Injection (Shellshock) |
2014-09-24 | CUPS Filter Bash Environment Variable Code Injection (Shellshock) |
2014-09-24 | Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner |
2014-09-24 | Apache mod_cgi Bash Environment Variable Code Injection (Shellshock) |
2015-12-01 | Advantech Switch Bash Environment Variable Code Injection (Shellshock) |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-12-04 | Name : The remote host is missing a vendor-supplied security patch. File : check_point_gaia_sk102673.nasl - Type : ACT_GATHER_INFO |
2016-02-02 | Name : The remote Solaris system is missing a security patch for third-party software. File : solaris11_bash_20141031_2.nasl - Type : ACT_GATHER_INFO |
2015-12-30 | Name : The remote VMware ESX host is missing a security-related patch. File : vmware_VMSA-2014-0010_remote.nasl - Type : ACT_GATHER_INFO |
2015-08-25 | Name : The remote IBM Storwize V7000 Unified device is affected by multiple vulnerab... File : ibm_storwize_1_5_0_4.nasl - Type : ACT_GATHER_INFO |
2015-04-06 | Name : The remote web server is affected by a remote code execution vulnerability. File : bash_cve_2014_6278.nasl - Type : ACT_ATTACK |
2015-03-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-164.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-63.nasl - Type : ACT_GATHER_INFO |
2015-01-19 | Name : The remote Solaris system is missing a security patch for third-party software. File : solaris11_bash_20141031.nasl - Type : ACT_GATHER_INFO |
2014-12-22 | Name : The remote device is affected by multiple vulnerabilities. File : juniper_space_jsa10648.nasl - Type : ACT_GATHER_INFO |
2014-11-26 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-11-26 | Name : The remote Cisco TelePresence Conductor device is affected by a command injec... File : cisco_telepresence_conductor_CSCur02103.nasl - Type : ACT_GATHER_INFO |
2014-11-13 | Name : The remote host is affected by a code injection vulnerability known as Shells... File : mcafee_ngfw_SB10085.nasl - Type : ACT_GATHER_INFO |
2014-11-12 | Name : The remote host has an application installed that is affected by multiple vul... File : vmware_vcenter_converter_2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-11-12 | Name : The remote host is affected by a code injection vulnerability known as Shells... File : mcafee_web_gateway_sb10085.nasl - Type : ACT_GATHER_INFO |
2014-11-11 | Name : The remote host is affected by a code injection vulnerability known as Shells... File : mcafee_email_gateway_SB10085.nasl - Type : ACT_GATHER_INFO |
2014-11-11 | Name : The remote host is missing a vendor-supplied security patch. File : cisco_cups_CSCur05454.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2014-1354.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1311.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1294.nasl - Type : ACT_GATHER_INFO |
2014-11-06 | Name : The remote host has a virtualization appliance installed that is affected by ... File : vcenter_operations_manager_vmsa_2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-11-04 | Name : The remote host has a device management application installed that is affecte... File : vmware_workspace_portal_vmsa2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-11-03 | Name : The remote SIP server uses scripts that allow remote command execution via Sh... File : shellshock_sip_invite.nasl - Type : ACT_ATTACK |
2014-11-03 | Name : The remote security device is missing a vendor-supplied security patch. File : cisco-sa-CSCur01959-asa-cx.nasl - Type : ACT_GATHER_INFO |
2014-11-03 | Name : The management application installed on the remote host is affected by a comm... File : cisco-sa-CSCur01959-prsm.nasl - Type : ACT_GATHER_INFO |
2014-11-03 | Name : The remote host is affected by a command injection vulnerability. File : vmware_nsx_vmsa_2014_0010.nasl - Type : ACT_GATHER_INFO |
2014-10-31 | Name : The remote host has a virtualization appliance installed that is affected by ... File : vmware_vsphere_replication_vmsa_2014_0010.nasl - Type : ACT_GATHER_INFO |
2014-10-31 | Name : The remote host is running a vulnerable version of Bash. File : cisco_ucs_director_CSCur02877.nasl - Type : ACT_GATHER_INFO |
2014-10-28 | Name : The remote host has a mail agent installed that allows remote command executi... File : shellshock_mail_agents.nasl - Type : ACT_DESTRUCTIVE_ATTACK |
2014-10-27 | Name : The remote device is running a version of NX-OS that is affected by Shellshock. File : cisco-sa-20140926-bash-nxos.nasl - Type : ACT_GATHER_INFO |
2014-10-21 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-595.nasl - Type : ACT_GATHER_INFO |
2014-10-21 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-594.nasl - Type : ACT_GATHER_INFO |
2014-10-21 | Name : The version of Cisco TelePresence Video Communication Server installed on the... File : cisco_telepresence_vcs_CSCur01461.nasl - Type : ACT_GATHER_INFO |
2014-10-20 | Name : The remote host is affected by a remote code execution vulnerability. File : palo_alto_PAN-SA-2014-0004.nasl - Type : ACT_GATHER_INFO |
2014-10-17 | Name : The remote host is missing a Mac OS X update that fixes multiple vulnerabilit... File : macosx_10_10.nasl - Type : ACT_GATHER_INFO |
2014-10-17 | Name : The remote host is missing a Mac OS X update that fixes multiple security iss... File : macosx_SecUpd2014-005.nasl - Type : ACT_GATHER_INFO |
2014-10-16 | Name : The remote host has a virtualization appliance installed that is affected by ... File : vmware_vcenter_server_appliance_vmsa-2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-10-13 | Name : The remote Solaris system is missing a security patch for third party software. File : solaris11_bash_2014_10_07.nasl - Type : ACT_GATHER_INFO |
2014-10-13 | Name : A system shell on the remote host is vulnerable to command injection. File : bash_cve_2014_7169.nasl - Type : ACT_ATTACK |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-419.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-418.nasl - Type : ACT_GATHER_INFO |
2014-10-10 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-567.nasl - Type : ACT_GATHER_INFO |
2014-10-10 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL15629.nasl - Type : ACT_GATHER_INFO |
2014-10-09 | Name : The remote host is missing Sun Security Patch number 149080-02 File : solaris9_x86_149080.nasl - Type : ACT_GATHER_INFO |
2014-10-09 | Name : The remote host is missing Sun Security Patch number 149079-03 File : solaris9_149079.nasl - Type : ACT_GATHER_INFO |
2014-10-06 | Name : A system shell on the remote host is vulnerable to command injection. File : bash_remote_code_execution2.nasl - Type : ACT_DESTRUCTIVE_ATTACK |
2014-10-06 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201409-09.nasl - Type : ACT_GATHER_INFO |
2014-10-03 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_81e2b3084a6c11e4b7116805ca0b3d42.nasl - Type : ACT_GATHER_INFO |
2014-10-02 | Name : The remote VMware ESX host is missing a security-related patch. File : vmware_VMSA-2014-0010.nasl - Type : ACT_GATHER_INFO |
2014-09-30 | Name : The remote FTP server is affected by a remote code execution vulnerability. File : proftpd_bash_injection.nasl - Type : ACT_ATTACK |
2014-09-30 | Name : The remote host is is affected by a remote code execution vulnerability, comm... File : macosx_shellshock_update.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-190.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11295.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11514.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11527.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11718.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-563.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-564.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1306.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote mail server uses scripts that allow remote command execution via S... File : shellshock_postfix_filters.nasl - Type : ACT_ATTACK |
2014-09-29 | Name : The remote mail server allows remote command execution via Shellshock. File : shellshock_qmail.nasl - Type : ACT_ATTACK |
2014-09-29 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20140926_bash_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2014-09-29 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_bash-140926.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote host is missing Oracle Security Patch number 126546-06 File : solaris10_126546-06.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11360.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Fedora host is missing a security update. File : fedora_2014-11503.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20140924_bash_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1306.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3035.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201409-10.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1306.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote host is missing Oracle Security Patch number 126547-06 File : solaris10_x86_126547-06.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote host is missing Oracle Security Patch number 149079-01 File : solaris9_149079-01.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote host is missing Oracle Security Patch number 149080-01 File : solaris9_x86_149080-01.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2363-2.nasl - Type : ACT_GATHER_INFO |
2014-09-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2363-1.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2014-267-01.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : A system shell on the remote host is vulnerable to command injection. File : bash_remote_code_execution_telnet.nasl - Type : ACT_ATTACK |
2014-09-25 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1293.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3032.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_71ad81da441411e4a33e3c970e169bc2.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-186.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-559.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1293.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2014-1294.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1293.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_bash-140919.nasl - Type : ACT_GATHER_INFO |
2014-09-25 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2362-1.nasl - Type : ACT_GATHER_INFO |
2014-09-24 | Name : A system shell on the remote host is vulnerable to command injection. File : bash_remote_code_execution.nasl - Type : ACT_ATTACK |
2014-09-24 | Name : The remote web server is affected by a remote code execution vulnerability. File : bash_cve_2014_6271_rce.nasl - Type : ACT_ATTACK |
2012-09-26 | Name : The remote host is missing Sun Security Patch number 126546-10 File : solaris10_126546.nasl - Type : ACT_GATHER_INFO |
2012-09-17 | Name : The remote host is missing Sun Security Patch number 126547-10 File : solaris10_x86_126547.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-03-13 21:22:23 |
|
2025-02-07 17:21:29 |
|
2025-01-07 00:24:01 |
|
2024-11-28 12:42:24 |
|
2024-07-24 21:28:05 |
|
2021-11-18 05:23:20 |
|
2021-11-10 09:23:39 |
|
2021-11-05 21:23:20 |
|
2021-05-04 12:33:47 |
|
2021-04-22 01:40:56 |
|
2021-02-02 05:22:46 |
|
2021-01-26 21:23:20 |
|
2020-05-23 13:17:05 |
|
2020-05-23 00:42:01 |
|
2019-10-10 05:19:30 |
|
2019-09-27 21:19:48 |
|
2019-03-19 12:06:32 |
|
2018-12-01 00:18:57 |
|
2018-10-10 00:19:52 |
|
2018-08-09 09:19:22 |
|
2017-12-05 13:24:05 |
|
2017-10-05 09:23:10 |
|
2017-09-17 09:23:30 |
|
2017-09-13 09:23:26 |
|
2017-09-03 09:24:00 |
|
2017-04-26 13:20:57 |
|
2017-01-07 09:25:42 |
|
2017-01-03 09:22:54 |
|
2016-12-08 09:23:32 |
|
2016-11-29 00:24:56 |
|
2016-06-29 01:16:23 |
|
2016-06-21 09:26:33 |
|
2016-06-17 09:28:33 |
|
2016-04-27 01:08:49 |
|
2016-03-07 17:24:18 |
|
2016-03-04 09:23:56 |
|
2016-03-04 05:23:48 |
|
2016-02-03 13:27:47 |
|
2015-12-31 13:26:07 |
|
2015-12-01 21:23:43 |
|
2015-10-18 17:22:51 |
|
2015-10-04 13:23:56 |
|
2015-09-25 13:23:54 |
|
2015-08-27 13:38:37 |
|
2015-07-24 13:29:09 |
|
2015-07-18 13:28:15 |
|
2015-07-13 21:26:55 |
|
2015-06-10 13:27:35 |
|
2015-05-19 21:28:55 |
|
2015-05-14 21:28:22 |
|
2015-05-12 13:28:19 |
|
2015-05-12 09:28:01 |
|
2015-04-24 13:28:46 |
|
2015-04-14 13:28:44 |
|
2015-04-10 09:26:26 |
|
2015-04-07 13:28:42 |
|
2015-03-31 13:28:45 |
|
2015-03-31 09:26:43 |
|
2015-03-27 13:28:31 |
|
2015-03-27 09:26:52 |
|
2015-03-21 00:26:16 |
|
2015-03-20 00:26:16 |
|
2015-03-18 09:27:22 |
|
2015-03-13 17:22:52 |
|
2015-03-13 00:22:17 |
|
2015-03-12 09:23:38 |
|
2015-03-07 13:24:35 |
|
2015-02-26 13:24:15 |
|
2015-02-17 13:24:57 |
|
2015-02-05 13:23:45 |
|
2015-01-31 13:23:07 |
|
2015-01-22 13:24:59 |
|
2015-01-21 13:27:02 |
|
2015-01-13 13:23:40 |
|
2014-12-24 09:23:58 |
|
2014-12-23 13:26:36 |
|
2014-12-07 13:26:18 |
|
2014-12-03 09:27:14 |
|
2014-12-02 21:25:51 |
|
2014-11-28 13:27:33 |
|
2014-11-27 13:28:35 |
|
2014-11-25 21:26:39 |
|
2014-11-21 21:22:23 |
|
2014-11-20 09:23:43 |
|
2014-11-19 05:34:52 |
|
2014-11-18 09:22:23 |
|
2014-11-16 21:25:17 |
|
2014-11-14 13:28:50 |
|
2014-11-14 13:26:28 |
|
2014-11-14 13:24:27 |
|
2014-11-13 13:27:10 |
|
2014-11-12 13:27:18 |
|
2014-11-08 13:31:55 |
|
2014-11-07 21:23:51 |
|
2014-11-07 13:26:25 |
|
2014-11-05 13:29:13 |
|
2014-11-05 13:27:59 |
|
2014-11-04 13:27:33 |
|
2014-11-01 13:26:40 |
|
2014-10-31 13:25:24 |
|
2014-10-30 21:27:03 |
|
2014-10-30 13:22:55 |
|
2014-10-29 13:24:30 |
|
2014-10-28 13:26:30 |
|
2014-10-28 13:24:53 |
|
2014-10-24 21:23:09 |
|
2014-10-24 13:27:20 |
|
2014-10-22 13:25:59 |
|
2014-10-21 13:26:04 |
|
2014-10-18 13:26:11 |
|
2014-10-17 13:26:49 |
|
2014-10-17 13:25:29 |
|
2014-10-16 13:26:41 |
|
2014-10-16 13:25:35 |
|
2014-10-12 13:27:28 |
|
2014-10-11 13:26:24 |
|
2014-10-10 13:27:31 |
|
2014-10-10 13:25:53 |
|
2014-10-08 13:25:05 |
|
2014-10-07 21:24:25 |
|
2014-10-05 13:27:03 |
|
2014-10-04 13:31:42 |
|
2014-10-04 13:29:26 |
|
2014-10-03 21:24:13 |
|
2014-10-03 13:27:19 |
|
2014-10-02 13:27:43 |
|
2014-10-01 21:24:50 |
|
2014-10-01 13:27:24 |
|
2014-09-30 13:27:33 |
|
2014-09-28 13:28:48 |
|
2014-09-27 13:28:22 |
|
2014-09-27 00:23:03 |
|
2014-09-26 13:28:59 |
|
2014-09-26 13:27:29 |
|
2014-09-26 13:25:26 |
|
2014-09-25 21:24:17 |
|
2014-09-25 00:23:56 |
|