Lucene search

K
freebsdFreeBSD512D1301-49B9-11E4-AE2C-C80AA9043978
HistorySep 27, 2014 - 12:00 a.m.

bash -- remote code execution

2014-09-2700:00:00
vuxml.freebsd.org
34

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.973

Percentile

99.9%

Note that this is different than the public “Shellshock”
issue.
Specially crafted environment variables could lead to remote
arbitrary code execution. This was fixed in bash 4.3.27, however
the port was patched with a mitigation in 4.3.25_2.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchbash< 4.3.25_2UNKNOWN
FreeBSDanynoarchbash-static< 4.3.25_2UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.973

Percentile

99.9%