Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you use BASH shell environment
Just an FYI, https://access.redhat.com/security/cve/CVE-2014-6271, I wouldn' t say it' s as bad as heartbleed but it' s definitely not good.
Regards,
Matthew
- « Previous
- Next »
22 REPLIES 22
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did create custom rules in my sensors to drop traffic matching these sigs, as the built rule default action is alert. Might want to be aware of that!@teedub Looks like the updated sig has default action to block now. v553 Thanks for the link; all interesting stuff to read over.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The IPS signature is called " Bash.Function.Definitions.Remote.Code.Execution" . It applies to servers and clients, OS=" Other,Linux" and is dated 2014-09-29.
I found it using a filter on the modification date...
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortinet has released an Info page on Fortiguard.com:
http://www.fortiguard.com/advisory/FG-IR-14-030/
Contains " products affected" , the use of the IPS signature on FortiGates and references. Seems there are 4 CVEs now on this topic.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!

- « Previous
- Next »