Re: Re: Bash exploit in the wild
By: Mro to Ree on Fri Sep 26 2014 04:01 pm
> i'm not so sure it's as bad as heartbleed, though.
It's worse. Heartbleed was "only" information disclosure and only impacted one
v
ersion for a short period of time, so not many embedded devices had it, and
thos
e that did were still in active maintenance mode.
The bash bug is remote execution, and has existed for about 25 years. Many
devi
ces which include bash have been shipped and are well past their support
date (t
hink smart TVs, routers, DVD and Blu-Ray players, etc) and will never be
fixed b
y the manufacturer.
---
http://DuckDuckGo.com/ a better search engine that respects your privacy.
■ Synchronet ■ My Brand-New BBS (All the cool SysOps run STOCK!)
|