Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2014-7186

Description

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.

POC

Reference

- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html

- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html

- http://www-01.ibm.com/support/docview.wss?uid=swg21685541

- http://www-01.ibm.com/support/docview.wss?uid=swg21685733

- http://www.qnap.com/i/en/support/con_show.php?cid=61

- https://kc.mcafee.com/corporate/index?page=content&id=SB10085

- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183

Github

- https://github.com/9069332997/session-1-full-stack

- https://github.com/ARPSyndicate/cvemon

- https://github.com/BahrainMobilityInternational/BMI-02

- https://github.com/CyberlearnbyVK/redteam-notebook

- https://github.com/EvanK/shocktrooper

- https://github.com/Gandhiprakash07/Trail01

- https://github.com/HttpEduardo/ShellTHEbest

- https://github.com/MrCl0wnLab/ShellShockHunter

- https://github.com/NINNiT/shellshock-lab

- https://github.com/Reh46/WEB1

- https://github.com/SaltwaterC/sploit-tools

- https://github.com/UMDTERPS/Shell-Shock-Update

- https://github.com/abdullah89255/Shellshock

- https://github.com/abdulrahmanasdfghj/brubru

- https://github.com/ankh2054/linux-pentest

- https://github.com/botaktrade/ExnessID.com

- https://github.com/demining/ShellShock-Attack

- https://github.com/dokku-alt/dokku-alt

- https://github.com/eduardo-paim/ShellTHEbest

- https://github.com/ericlake/fabric-shellshock

- https://github.com/foobarto/redteam-notebook

- https://github.com/giterlizzi/secdb-feeds

- https://github.com/googleinurl/Xpl-SHELLSHOCK-Ch3ck

- https://github.com/hannob/bashcheck

- https://github.com/httpEduardo/ShellTHEbest

- https://github.com/inspirion87/w-test

- https://github.com/jdauphant/patch-bash-shellshock

- https://github.com/meherarfaoui09/meher

- https://github.com/mrigank-9594/Exploit-Shellshock

- https://github.com/mubix/shellshocker-pocs

- https://github.com/opragel/shellshockFixOSX

- https://github.com/opsxcq/exploit-CVE-2014-6271

- https://github.com/readloud/ShellShockHunter-v1.0

- https://github.com/sandinak/sudosh

- https://github.com/securetiger/Exploit-Shellshock

- https://github.com/trhacknon/Xpl-SHELLSHOCK-Ch3ck

- https://github.com/trhacknon/exploit-CVE-2014-6271

- https://github.com/xdistro/ShellShock