SECURITY THREATIf you are running or have "bash" installed on any of your systems/devices that use versions between 1.14 to 3.4 you are vulnerable. This is a very large threat. It allows the attack to execute code and commands on the target system. To check your version in the command line run "bash --version" to check, if you fall into that version range please update your package manage and update/patch immediately.
To test if you are at risk run:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
If the console prints:
vulnerable
this is a test
You are not protected, once patched you should see:
bash: warning: x: ignoring function definition attempt
bash: error importing function definition for `x'
this is a test
Best of luck everyone!
Link:
https://isc.sans.edu/foru...mins+time+to+patch+/18703Link:
http://www.zdnet.com/unix...ux-bash-...ed-7000034021/Thank you.
____________