Worse than Heartbleed? Today’s Bash bug could be breaking security for years

Linux users got a nasty surprise today, as a security team at Red Hat uncovered a subtle but dangerous bug in the Bash shell, one of the most versatile and widely used utilities in Linux. It’s being called the Bash bug, or Shellshock. When accessed properly, the bug allows for an attacker’s code to be executed as soon as the shell is invoked, leaving the door open for a wide variety of attacks. Worse yet, it appears the bug has been present in enterprise Linux software for a long time, so patching every instance may be easier said than done. Red Hat and Fedora have already released patches for the bug.

Continue reading…

The Verge – All Posts

Leave a Comment