Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CGI:BASH-CODE-INJECTION

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Multiple Products Bash Code Injection Vulnerability

Release Date

2014/09/25

Update Number

2422

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Multiple Products Bash Code Injection Vulnerability


This signature detects attempts to exploit a known vulnerability against GNU Bash. A successful attack can lead to arbitrary code execution.

Extended Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

Affected Products

  • Gnu bash 1.14.0
  • Gnu bash 1.14.1
  • Gnu bash 1.14.2
  • Gnu bash 1.14.3
  • Gnu bash 1.14.4
  • Gnu bash 1.14.5
  • Gnu bash 1.14.6
  • Gnu bash 1.14.7
  • Gnu bash 2.0
  • Gnu bash 2.01
  • Gnu bash 2.01.1
  • Gnu bash 2.02
  • Gnu bash 2.02.1
  • Gnu bash 2.03
  • Gnu bash 2.04
  • Gnu bash 2.05
  • Gnu bash 3.0
  • Gnu bash 3.0.16
  • Gnu bash 3.1
  • Gnu bash 3.2
  • Gnu bash 3.2.48
  • Gnu bash 4.0
  • Gnu bash 4.1
  • Gnu bash 4.2
  • Gnu bash 4.3

References

  • BugTraq: 70166
  • BugTraq: 70103
  • CVE: CVE-2014-6277
  • CVE: CVE-2014-6278
  • CVE: CVE-2014-7169
  • CVE: CVE-2014-6271
  • URL: http://seclists.org/oss-sec/2014/q3/649
  • URL: https://community.rapid7.com/community/infosec/blog/2015/12/01/r7-2015-25-advantech-eki-multiple-known-vulnerabilities
  • URL: https://access.redhat.com/articles/1200223
  • URL: https://access.redhat.com/node/1200223

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out