VMware releases software updates to fix Shellshock Security Vulnerabilities
VMware, one of several major technology companies, began releasing software updates to handle GNU Bash's Shellshock security vulnerabilities. Software affected by this vulnerability includes ESX, vCenter Server Appliance, Horizon Workspace, IT Business Management Suite, vCenter Log Insight, vCenter Operations Manager, vCenter Site Recovery Manager, vCloud Application ctor, vCloud Automation Center, vCloud ctor Appliance, vFabric Postgres, VMware Data Recovery, VMware Mirage Gateway, vSphere Replication and vSphere Storage Appliance. however, ESXi and Windows-based products are not affected.
From now on, Bash library updates are only for ESX, vCenter Server Appliance, IT Business Management Suite, vCenter Log Insight, vCenter Site Recovery Manager, vCloud Director Appliance, vFabric Postgres, VMware Data Recovery, VMware Mirage Gateway, vSphere Replication, and vSphere Storage Appliance.
Before patches are provided for all products, VMware recommends that its customers only allow access to trusted customers and IP addresses.
ShellShock Security Vulnerability (CVE-2014-6271) was detected quickly fixed and released patches, but later found some of the relevant vulnerabilities, including: CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE-2014-6278. VMware points out that it will soon release software updates to fix all of these vulnerabilities.
VMware's security engineers closely follow information from the security community. Several other software companies, including Apple and Oracle, have begun releasing various software update patches to fix the vulnerability.
Gitlab-shell is affected by Bash CVE-2014-6271 Vulnerability
Linux security vulnerability exposure Bash is more serious than heartbleed
The solution is to upgrade Bash. Please refer to this article.
Bash remote parsing command execution vulnerability Test Method
This article permanently updates the link address: