Oracle urgently fixes Bash vulnerabilities, and more than 40 products are still waiting in line
The Shellshock vulnerability was initially estimated to have affected dozens of Oracle products. However, the patches released by Oracle only cover a few products. Currently, there are more unpatched products, includes more than 40 Big Data Appliance, Oracle Communications, Oracle Fusion, and Oracle Switch ES1-24.
Oracle released updates last week to fix Bash Shell CVE-2014-7169 vulnerabilities in some products, but more than 40 products are not yet released.
Related Websites: Oracle Security notice
The first detected Bash Shell vulnerability is a CVE-2014-6271, but the outside world soon found that the patch for this vulnerability is neither complete nor correct, and thus released a CVE-2014-7169 vulnerability notice, the Oracle vulnerability was fixed for CVE-2014-7169 and said it would allow hackers to execute arbitrary programs remotely without authentication.
The vulnerability was initially estimated to have affected dozens of Oracle products. However, the patches released by Oracle only cover a few products, including Oracle Database Appliance, Oracle Exadata Storage Server Software, Oracle Exalogic, Oracle Exalytics, Oracle Linux 4/5/6/7, and Oracle Solaris Operating System 8/9/10/11.
Release: This is a product that has released a patch.
More than 40 products, including Big Data Appliance, Oracle Communications, Oracle Fusion, and Oracle Switch ES1-24, are affected by vulnerabilities that are equally affected but not patched.
Oracle said the company is still investigating and will provide patches to various products as soon as possible, and it is recommended that customers deploy product updates with existing patches as soon as possible.
Gitlab-shell is affected by Bash CVE-2014-6271 Vulnerability
Linux security vulnerability exposure Bash is more serious than heartbleed
The solution is to upgrade Bash. Please refer to this article.
This article permanently updates the link address: