Skip to content

Latest commit

 

History

History
65 lines (42 loc) · 1.48 KB

README.md

File metadata and controls

65 lines (42 loc) · 1.48 KB

bashcheck

Test script for Shellshock and related vulnerabilities

background

The Bash vulnerability that is now known as Shellshock had an incomplete fix at first. There are currently 4 public and one supposedly non-public vulnerability.

usage

Just run script: ./bashcheck

CVE-2014-6271

The original vulnerability.

CVE-2014-7169

Further parser error, found by Tavis Ormandy (taviso).

CVE-2014-7186

Out of bound memory read error in redir_stack.

CVE-2014-7187

Off-by-one error in nested loops. (check only works when Bash is built with -fsanitize=address)

CVE-2014-6277

Not yet published parser bug by Michal Zalewski (lcamtuf).

CVE-2014-6278

Another not yet published parser bug by Michal Zalewski (lcamtuf).