With all the scare regarding CVE-2014-6271, I've found little concrete information regarding the vulnerability's surface area. In particular, does an individual require terminal access to execute this exploit? I am aware that CGI services that call out to the shell can indirectly provide access to this vulnerability (as per The bash vulnerability CVE-2014-6271 . Can it affect my CGI perl scripts? How to understand this?), but what other vectors of attack exist?
Does bash exploit (CVE-2014-6271) require terminal access to utilize?
138 Views Asked by Justin Bell At
1
There are 1 best solutions below
Related Questions in BASH
- When does Bash read heredocs?
- Why `set -o pipefail` gives different output even though the pipe is not failing
- Run an external command within jq to manipulate each values of a particular key
- API key 401 error in .env.development file
- How to "Enable mobile data" on a Huawei E3372 4G USB dongle using a bash script in Windows
- ImageMagick / Bash : pipe ignored(?) when filename format variable used
- MacOS Bash-Script: while read p and echo
- Parse command line arguments and write useful usage message without additional code
- JQ JSON - Values to Array
- why variable substitution is so different?
- postbank_pdf2csv: how to setup with Cygwin in Windows?
- Custom Bash functions & custom statements - Need some advice
- unexpected operator == in square brackets when trying to use gum lib
- How to disable a bash builtin inside a docker container
- Use sed or rename find series of alphabet then replace with with the same alphabet and a dash -
Related Questions in EXPLOIT
- Nop Sled, can you explain it to me?
- ln fails when trying to manully trigger race conditoin
- Solving mprotect() syscall failure
- Segmentation fault on buffer buffer overflow
- Exploiting a buffer overflow read operation
- Wargame payload segfaults when used as such
- Making a system/program vulnerable to exploits
- Format string bugs - exploitation
- return to libc - problem
- how to safely write out user generated text in xhtml
- Buffer overflow weird behaviour
- Buffer overflow is still feseable?
- Firefox "Script error" in resource://gre/components/nsLoginManager.js
- Why the EIP contents do not execute?
- POSIX compliant way to tell if system rebooted?
Related Questions in SHELLSHOCK-BASH-BUG
- Can shellshock redirect my visits on nginx?
- Why can't I get the ShellShock Bash bug to reproduce on Bash 4.2.0?
- What is the correct way to export a bash function after the shellshock updates?
- How do I restore CronTab to my WebMin system
- Why isn't my bash 4.1.2 package vulnerable to shellshock? Is my test wrong?
- Is the behavior behind the Shellshock vulnerability in Bash documented or at all intentional?
- with Ansible and apt, how do I update bash to for the remotely exploitable security vulnerability CVE-2014-6271?
- Impact of BASH bug on Azure Websites, Cloud Services and SQL Database?
- Does bash exploit (CVE-2014-6271) require terminal access to utilize?
- I'm having difficulty understanding the Shellshock vulnerability verification
- Strange Bash function export for the Shellshock bug
- what exactly env command do?
- patching bash shell shock bug from source
- What is a specific example of how the Shellshock Bash bug could be exploited?
- Shellshock Bash bug preload workaround
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
No, looks like apache's mod_cgi and mod_cgid are gateways for bash environment code execution with a crafted HTTP request header.