Examples of CentOS and Ubuntu Server Bash bug fixes

Source: Internet
Author: User
Tags echo date

Linux official built-in bash recently found a very serious security vulnerability, hackers can use the bash to fully control the target system and launch attacks, in order to avoid your Linux server affected, we recommend that you complete the bug fix as soon as possible.

The following is a small series for everyone to attach the most common Linux kernel CentOS and Ubuntu Server Repair Bash Vulnerability Ultimate Repair method.

650) this.width=650; "src=" http://183.61.143.148/group1/M00/02/7D/tz2PlFRcPN7SU7MJAAFFS_dSTiU724.jpg "/>

Software and systems that have been successfully exploited have been identified: all Linux operating systems installed with GNU Bash version less than or equal to 4.3.

"Bash Vulnerability description"

The vulnerability stems from the special environment variables created before the bash shell that you invoke, which can contain code and be executed by bash.

"Vulnerability Detection Method"

Using the vulnerability Detection command in a server command: Env-i x= ' () {(a) = ' bash-c ' echo date '; Cat Echo

Before the repair, the current system time is displayed, the server this vulnerability has not been repaired, please fix it, the following is attached to the Linux system repair program, mainly includes: CentOS and Ubuntu System final repair solution.

First, the CentOS Final Repair Bash Vulnerability scenario

In the Server command box, type the following command to upgrade to fix the vulnerability:

Yum Clean All

Yum Makecache

YUM-Y Update Bash

Second, Ubuntu final Fix bash Vulnerability scheme, please run the following command

Apt-cache gencaches

Apt-get-y Install--only-upgrade Bash

After the above method is repaired, we run the detection command again: Env-i x= ' () {(a) = ' bash-c ' echo date '; Cat Echo

If the output is repaired with a patch scenario: date, which means that the output contains a date string, the bug fix succeeded.

This fix will not have any effect, if your script uses the above method to define environment variables, your script execution will error after repair, in order to prevent unexpected situation, we recommend that you first backup the Linux server system disk before executing the command. more system operation and Maintenance tutorial knowledge can be sent to e-mentor network learning.


This article is from the "Add Language" blog, please make sure to keep this source http://yuguotianqing.blog.51cto.com/9292883/1575266

Examples of CentOS and Ubuntu Server Bash bug fixes

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.