Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Matthew_Mollenhauer
New Contributor III

If you use BASH shell environment

Just an FYI, https://access.redhat.com/security/cve/CVE-2014-6271, I wouldn' t say it' s as bad as heartbleed but it' s definitely not good. Regards, Matthew
22 REPLIES 22
jtfinley

I did create custom rules in my sensors to drop traffic matching these sigs, as the built rule default action is alert. Might want to be aware of that!
@teedub Looks like the updated sig has default action to block now. v553 Thanks for the link; all interesting stuff to read over.
ede_pfau
SuperUser
SuperUser

The IPS signature is called " Bash.Function.Definitions.Remote.Code.Execution" . It applies to servers and clients, OS=" Other,Linux" and is dated 2014-09-29. I found it using a filter on the modification date...
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ede_pfau

Fortinet has released an Info page on Fortiguard.com: http://www.fortiguard.com/advisory/FG-IR-14-030/ Contains " products affected" , the use of the IPS signature on FortiGates and references. Seems there are 4 CVEs now on this topic.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors