A critical vulnerability dubbed Shellshock was disclosed in GNU Bash, a command shell used on most Linux and Unix systems and on Apple’s Mac OS X. The flaw was reported by researcher Stéphane Chazelas and had existed for more than two decades.
What happened
- The bug (CVE-2014-6271) let attackers execute commands by placing code in environment variables, for example through web server CGI scripts.
- It received the maximum severity score of 10 out of 10.
- The first patches proved incomplete, leading to further fixes and additional CVEs.
- Attackers began scanning for and exploiting vulnerable servers within hours of disclosure.
Why it mattered
Coming months after Heartbleed, Shellshock reinforced concerns about the security of ageing open-source components that underpin much of the internet, including routers and embedded devices that are hard to patch.
Lessons for organisations
Organisations should know where core components such as shells and libraries are embedded in their systems and devices, apply emergency patches quickly, and follow up as fixes are updated. A vulnerability management process, as required by ISO/IEC 27001, makes this faster.
Sources: The Register, Fortune
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.