|
关于该漏洞: Q w9 M! l' H8 [" M7 y
你好,一个被指比“心脏出血”还要严重的Linux安全漏洞被发现,那就是ShellShock: CVE-2014-6271漏洞,可以让攻击者远程执行任意命令,完全控制您的服务器,比“心脏出血”更低的操作门槛,让它比前者更加危险。下面是漏洞提示原文:
$ d" ~. V+ r. j# w2 i. h5 C1 j% |) a& ] "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution."7 y+ o- g n& l+ O
% |$ _; |/ a4 ?' u如何验证
7 n0 w* H. ~; l8 i4 {# s$ env x='() { :;}; echo vulnerable' bash -c 'echo hello' t4 O, C1 C# |6 r) y, E8 Q5 Z
在终端中运行上面的命令,如果返回有vulnerable,就说明这台服务器中枪了。
5 a4 V& y* `) Y8 Y) K6 f把命令中的bash替换成其他类型的shell,可以检查机器上其他shell是否中枪。
5 }9 \& ]8 d- Z9 V% A; j( ?! ]3 [+ \3 S
使用网站卫士修复安全问题9 e8 `" b- p5 H2 e1 Z
360网站卫士已经支持该漏洞的防护,为了您网站的安全,建议开启360网站卫士的防护功能。
G) i! s; T( M# B" D2 O8 `9 u& F注意:由于补丁修复的不完整,导致了CVE-2014-7169的爆出,可以绕过9月25日的官方补丁,导致任意文件读取漏洞。强烈建议在做好服务器补丁升级的同时,开启网站卫士的防护功能。 + F7 Z! [4 [% B. C! w4 ]1 y. S
- @7 |& u2 O: ^! ?1 |如何修复系统Bug
" `0 j! Z. X4 h8 Z, E* GNU官方补丁所在地址:http://seclists.org/oss-sec/2014/q3/6507 z% } d( y' m. T3 |# b# y: F
* 各大发行版的解决方法: U4 u% G" }& b- s+ t
$ O. m4 W7 N) G: D o, Y# E
Debian:
3 w2 p& _6 \" o S `- H 查看 https://www.debian.org/security/2014/dsa-3032
; V) h# P( C# @% r6 e' A) x
' W5 s) N" p+ P, ^- }Ubuntu:" j/ F' l) Z8 b, c6 z$ ~
查看 http://www.ubuntu.com/usn/usn-2362-1/
( e' ~+ U. o [; O8 u* g9 s7 p
* U6 O; o# I9 _$ l3 \. Y4 i* I$ FCentOS:
$ I/ A# R* f) _" D # yum -y update bash
- y# B3 ^& ^9 `% e2 j, L% s+ }9 r" J8 m
Fedora:% y& F; K( B T$ k. _* }+ \+ e
查看 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-62719 w/ r( s3 ] `2 H
' W0 i+ k6 E( `9 ^+ v& u
Redhat:7 D/ G3 c- b5 p9 u+ P4 J% I
| 产品 | 补丁包 | 详情 | | Red Hat Enterprise Linux 7 | bash-4.2.45-5.el7_0.2 | Red Hat Enterprise Linux | | Red Hat Enterprise Linux 6 | bash-4.1.2-15.el6_5.1 | Red Hat Enterprise Linux | | bash-4.1.2-15.el6_5.1.sjis.1 | Red Hat Enterprise Linux | | bash-4.1.2-9.el6_2.1 | Red Hat Enterprise Linux 6.2 AUS | | bash-4.1.2-15.el6_4.1 | Red Hat Enterprise Linux 6.4 EUS | | Red Hat Enterprise Linux 5 | bash-3.2-33.el5.1 | Red Hat Enterprise Linux | | bash-3.2-33.el5_11.1.sjis.1 | Red Hat Enterprise Linux | | bash-3.2-24.el5_6.1 | Red Hat Enterprise Linux 5.6 LL | | bash-3.2-32.el5_9.2 | Red Hat Enterprise Linux 5.9 EUS | | Red Hat Enterprise Linux 4 | bash-3.0-27.el4.2 | Red Hat Enterprise Linux 4 ELS |
4 O. I% V- _" N6 V) K: lNovel/SuSE:
% B5 n0 c2 h- [0 x' B" J9 e! I( h2 u 查看 http://support.novell.com/security/cve/CVE-2014-6271.html4 e7 R2 X' V9 v. |) P. b3 U
& Y! D5 Z( v' S9 ]1 [* _& I
* 其他发行版也可以参照上面的方法自行编译,或者通过发行版内置的包管理器来更新bash。
7 l3 b7 O2 M* s$ E8 V |