Don’t do SECURITY. Do business SECURELY.

Shellshock flaw in Bash shell puts millions of systems at risk

A decades-old flaw in the Bash command shell allowed attackers to run code remotely on Linux, Unix, and Mac systems and many devices.

A critical vulnerability dubbed Shellshock was disclosed in GNU Bash, a command shell used on most Linux and Unix systems and on Apple’s Mac OS X. The flaw was reported by researcher Stéphane Chazelas and had existed for more than two decades.

What happened

  • The bug (CVE-2014-6271) let attackers execute commands by placing code in environment variables, for example through web server CGI scripts.
  • It received the maximum severity score of 10 out of 10.
  • The first patches proved incomplete, leading to further fixes and additional CVEs.
  • Attackers began scanning for and exploiting vulnerable servers within hours of disclosure.

Why it mattered

Coming months after Heartbleed, Shellshock reinforced concerns about the security of ageing open-source components that underpin much of the internet, including routers and embedded devices that are hard to patch.

Lessons for organisations

Organisations should know where core components such as shells and libraries are embedded in their systems and devices, apply emergency patches quickly, and follow up as fixes are updated. A vulnerability management process, as required by ISO/IEC 27001, makes this faster.

Sources: The Register, Fortune

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights