/bashcheck

test script for shellshocker and related vulnerabilities

Primary LanguageShellCreative Commons Zero v1.0 UniversalCC0-1.0

bashcheck

test script for shellshocker and related vulnerabilities

background

The Bash vulnerability that is now known as shellshock had an incomplete fix at first. There are currently 4 public and one supposedly non-public vulnerability.

usage

Just run script: ./bashcheck

CVE-2014-6271

The original vulnerability.

CVE-2014-7169

Further parser error, found by Tavis Ormandy (taviso)

CVE-2014-7186

Out of bound memory read error in redir_stack.

CVE-2014-7187

Off-by-one error in nested loops. (check only works when Bash is built with -fsanitize=address)

CVE-2014-6277

Not yet published parser bug by Michal Zalewski (lcamtuf).