Security Alert: bash Code Injection Vulnerability
This morning got brought to attention by my colleague, Iwan regarding this bash Code breached. I am no linux or unix guy but when comes to security this is not to be play with especially in industry where security and compliance is highly evaluated. A security vulnerability was detected known as "Shell Shock" which is a bash shell commonly found in unix and linux platform. You can refer to CVE-2014-6271 , CVE-2014-7169 . VMware was fast to publish this discover as well and you can read the post here and also to follow up with this KB on what products will be impacted. So check back the KB to see which product from VMware is impacted and how to mitigate. Note: that ESXi are not impacted with this "Shell shock" vulnerability. As for other platforms, you would have to look back to your respective principle to find out if it is affected and the solution to resolve. Update 29th Sept 2014 As extracted from CSOOnline , CentOS versions 5-7, Ubuntu 10.04,...