2024 èä½æ¨©. ä¸è¨±è¤è£½ ãã©ã¤ãã·ã¼ããªã·ã¼
CVE-2014-6271 ã®ä»¶ã«ã¤ãã¦ãä½ãããã£ã¦ãªãè¨äºãæ£è¦ãããã®ã§ç°¡åã«ã¾ã¨ãã åé¡ç¹ ç°å¢å¤æ°ãç¹æ®ãªæååã®å ´åãBash ã¯ãããé¢æ°å®ç¾©ã¨ã¿ãªãï¼ãã®ä»æ§ãããããã©ããªã®ããã¨æã人ã¯/bin/shãbashã«ããã®ã¯ããããã¾ãããï¼ããã®ãã¸ãã¯ã«èª¤ãããããé¢æ°å®ç¾©ã§ãªãé¨åãèªã¿è¾¼ã¿ããã®é¨åãå®è¡ããã¦ãã¾ãã å½±é¿ç¯å² /bin/sh ã bash ã§ãªãã·ã¹ãã ã®å ´å æ示çã« bash ã¹ã¯ãªããã¨ãã¦èµ·åãããã¹ã¯ãªããã ããå½±é¿ãåããããã ã SSH ãµã¼ãã¼ã®å ´åãã¦ã¼ã¶ã¼ããã°ã©ã ãå®è¡ããå ´åã«ã¦ã¼ã¶ã¼ã®ã·ã§ã«ã使ç¨ããã®ã§ãããã§å½±é¿ãåãããã¨ãããã /bin/sh ã bash ã§ããã·ã¹ãã ã®å ´å system(3) ã popen(3) ãå é¨ã§ /bin/sh ãå©ç¨ãã¦ããã®ã§ãå½±é¿ã¯åºç¯ã«æ¸¡ãã CGI ç¹ã«è©±é¡ã«ãªã£ã¦
ã¹ãã¼ããã©ã³ãPCãªã©ãè¤æ°ã®ç«¯æ«ã®åæå©ç¨ãé »ç¹ã«è¡ã人ã¯ã1度ã«1ã¤ã®ç«¯æ«ã ããå©ç¨ãã人ã«æ¯ã¹ãææ決å®ãå ±æãæ åã¨ãã£ãèªç¥ããã³ææ å¶å¾¡ã«ããããè³ã®é¨åã®ç°ç½è³ªå¯åº¦ãä½ãââããã®ãããªç 究çµæãçºè¡¨ããè«æã9æ24æ¥ï¼ç¾å°æéï¼ãç±³ç§å¦éèªãPLOS ONEãã«æ²è¼ãããã è±ãµã»ãã¯ã¹å¤§å¦ã®ç 究ã«ããã¨ãã¹ãã¼ããã©ã³ããã¼ãPCãã®ä»ã®ã¡ãã£ã¢ç«¯æ«ãåæã«å©ç¨ããããããããã«ãã¿ã¹ã¯è¡åã«ããã人éã®è³ã®æ§é ãå¤ããã¨ããã ãã®ç 究ã¯ãé«åº¦ãªãã«ãã¿ã¹ã¯è¡åã¨ã注æåæ£æ¼«ããã³è½ã¡è¾¼ã¿ãä¸å®ãªã©ã®ææ çåé¡ã¨ã®éã«é¢é£æ§ãããã¨ããå¥ã®ç 究ãè£ä»ãããã®ã ã ãã®è«æãçºè¡¨ããç¥çµç§å¦è ã®ã±ãã»ãã¼ã»ãã¼æ°ã¨éäºè¯å¤ªå士ã¯ã75人ã®æ人被é¨è ã«ãã«ãã¿ã¹ã¯ã«é¢ãã質åãããå ¨å¡ã®è³ã®æ©è½çç£æ°å ±é³´ç»åï¼fMRIï¼ãæ®å½±ãã¦é¢é£æ§ã調ã¹ãã ãã®çµæããã«ãã¿ã¹ã¯
ï¼ï¼£ï¼®ï¼®ï¼Â KLï¼ãªã©ã³ãèªç©ºã®åç»ãè¦ã¦ãã¾ã£ããã次ã«ãªã©ã³ãã«è¡ã£ãæãæ©å ã«ããã¨å¿ãç©ãããããªããããããªãââãã¢ã ã¹ãã«ãã ã®ã¹ããã¼ã«ç©ºæ¸¯ã§ãå¿ãç©ã®æã¡ä¸»ãè¦ã¤ãã¦å±ãã¦ããããã¼ã°ã«ç¬ãã·ã£ã¼ããã¯ããæ´»èºãã¦ããã ã·ã£ã¼ããã¯ã®ä»äºã¯å空港ã®å°ç便ã§è¦ã¤ãã£ãå¿ãç©ããæã¡ä¸»ã®ä¹å®¢ã«å±ãããã¨ãä¹å¡ãæ©å ã§è¦ã¤ããï½ï¼°ï½ï½ï½ï½ ãªã©ã®å¿ãç©ãåãåãã¨ãå°çããã¼ãèµ°ãåã£ã¦ããã®éãå è¦ã§æã¡ä¸»ãæ¢ãåºãã ãè¨ç·´ã§ã¯çèãéãã¦è¾æ±å¼·ããæãããããã¦ãã¡ãã社交è½åããä¹å®¢ã®åå¿ã¯ç´ æ´ããããã¨è¨ç·´å£«ã¯è©±ãã KLï¼ã«ããã¨ãã½ã¼ã·ã£ã«ã¡ãã£ã¢ãéãã¦å¿ãç©ã«ã¤ãã¦ã®åãåãããå¤æ°å¯ãããããã¨ããã対å¿ãã¼ã ã®ä¸å¡ã¨ãã¦ã·ã£ã¼ããã¯ãæ¡ç¨ãããããã®åã¯ä¼ç¤¾ã«ã¨ã£ã¦æ¬å½ã«å¤§åãªåå¨ãã»ãã®èª°ã«ãã§ããªããã¨ããã£ã¦ããããã¨å°ä¸è·å¡ã¯ç®ãç´°ããã ç¹ã«èã
bashã«èå¼±æ§ã確èªãããã¨ãã¦é¨ãã«ãªã£ã¦ãã¾ããããã§ã¯CVE-2014-6271ã«é¢ããæ å ±ãã¾ã¨ãã¾ãã #è¨è¼å 容ã«ã¤ãã¦ã誤ã£ã¦ããã追è¨ããæ¹ãããçæ å ±ããããã¾ããã@piyokangoã¾ã§ãé£çµ¡ãé¡ããã¾ãã èå¼±æ§æ å ± èå¼±æ§ã®æ称 ShellShock Bashbug CVEçªå· Bashå¨ãã§çºè¡ããã¦ããCVEã¯6ã¤ããã®å 詳細ãä¸æãªã®ã2ã¤ã(CVE-2014-6277,CVE-2014-6278) CVE çºè¦è æ³å®è å¨ ç¹è¨ CVE-2014-6271 Stephane Chazelasæ° ä»»æã®ã³ã¼ãå®è¡ ShellShockã®çºç«¯ã¨ãªã£ããã°ã CVE-2014-7169 Tavis Ormandyæ° ä»»æã®ã³ã¼ãå®è¡ CVE-2014-6271ä¿®æ£æ¼ãã«ããèå¼±æ§ CVE-2014-7186 Redhat DoS ã¡ã¢ãªç ´å£(Out-of-Bo
Steven J. Vaughan-Nichols ï¼Special to ZDNET.comï¼Â ç¿»è¨³æ ¡æ£ï¼Â ç·¨éé¨ 2014-09-25 11:10 å¤ãã®UNIXããã³Linuxã®ã¦ã¼ã¶ã¼ã«å©ç¨ããã¦ãããBourne Again SHellï¼Bashï¼ãã«é大ãªã»ãã¥ãªãã£ãã¼ã«ãçºè¦ãããããã®ã»ãã¥ãªãã£ãã¼ã«ã¯Bashã«ããç°å¢å¤æ°ã®è©ä¾¡æ¹æ³ã«èµ·å ãã¦ãããããã«ã¼ã¯ç¹å¥ã«ä½æããå¤æ°ãç¨ãã¦ã»ãã¥ãªãã£ãã¼ã«ãçªããã·ã§ã«ã³ãã³ããå®è¡ã§ãããããã«ãããµã¼ãã¯ãããªãæ¬æ ¼çãªæ»æã«å¯¾ãã¦èå¼±ãªç¶æ ã¨ãªãã æ°ããä»ã®ã»ãã¥ãªãã£ãã¼ã«ã¨åæ§ã«ãä»åã®ã»ãã¥ãªãã£ãã¼ã«ãæªç¨ããã«ã¯é«ã¬ãã«ã®ã¢ã¯ã»ã¹æ¨©ãå¿ è¦ã ããããRed Hatã®ã»ãã¥ãªãã£ãã¼ã ã«ããã¨ãããã«ã¼ã¯ç¹å®ã®ãµã¼ãã¹ãã¢ããªã±ã¼ã·ã§ã³ãçµç±ãããã¨ã§ãèªè¨¼ãªãã«ãªã¢ã¼ãããç°å¢å¤æ°ãå ¥åããã»ãã¥ãªãã£ãã¼
ããæ°å¹´éãããã°ã©ãã³ã°çãªè¦³ç¹ã§è¦ãã¨ãç§ãæãã§ããã»ã©ã«ã¯é¢ç½ã¿ããªãã£ãã¨è¨ããããå¾ã¾ããããã®ãã¨ã¯ãæããä»ã®ããã°ã©ãã®çãããåæè¦ãã¨æãã¾ããããã§ãç§ã¯ãã®æéãããæå³ãå é»æéã¨æãã¦ãèªåã®éçºãã¼ã«ã®å¼·åã«åãçµãã§ãã¾ãããããã¦åææ¥ã«ãªãã¨ãBashã使ã£ã¦ ã¯ã¼ã¯ã¹ãã¼ã¹ ä½ãã«ç²¾ãåºãã¦ããã®ã§ãã æå¾ã«ã·ã§ã«ã使ã£ã¦çå£ã«ããã°ã©ãã³ã°ã«åãçµãã ã®ã¯ãããããæç«ãã¾ã å°çãæ¯é ãã¦ããé ã ã£ãã§ãããããä½å¹´ã触ãã¦ããªãã£ãè¨èªãæ¹ãã¦åãä¸ãããã®æã«èªåãæ¸ããã³ã¼ããè¦ç´ãã¦ã¿ãã¨ãããã«èªåãæé·ãããã¨ãããã¨ãå®æã§ãã¦ããªããªãã«é¢ç½ããã®ã§ãã 14å¹´åãç§ã¯âã³ã³ãã¯ããªã³ã¼ãã¯åªãã¦ããâã¨ããèãã«éåã¨å¾åãã¦ãã¾ãããã³ã¼ããå°ãªããã°ãããã¦Donât Repeat Yourselfï¼DRYï¼ã«å¾ãã°ããã°ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}