Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Shellshock (software bug)</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Shellshock_(software_bug)"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Shellshock_software_bug rootpage-Shellshock_software_bug skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Shellshock (software bug)</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">"Bash bug" redirects here. For the related bug reporting tool, see <a href="Bash_(Unix_shell)#Bug_reporting" title="Bash (Unix shell)">Bash (Unix shell) §&nbsp;Bug reporting</a>. For the arcade skill game, see <a href="Bashy_Bug" class="mw-redirect" title="Bashy Bug">Bashy Bug</a>.</div>
<style data-mw-deduplicate="TemplateStyles:r1305433154">
/* start https://en.wikipedia.org/ */


.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style>
<p class="mw-empty-elt">
</p>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */


.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}


/* end https://en.wikipedia.org/ */
</style><table class="infobox"><caption class="infobox-title">Shellshock</caption><tbody><tr><td colspan="2" class="infobox-image"><span typeof="mw:File"></span><div class="infobox-caption">A simple Shellshock logo, similar to the <a href="Heartbleed" title="Heartbleed">Heartbleed</a> bug logo.</div></td></tr><tr><th scope="row" class="infobox-label"><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE identifier(s)</a></th><td class="infobox-data"><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6271">2014-6271</a> (initial),<br><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6277">2014-6277</a>,<br> <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6278">2014-6278</a>,<br> <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7169">2014-7169</a>,<br> <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7186">2014-7186</a>,<br> <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7187">2014-7187</a></td></tr><tr><th scope="row" class="infobox-label">Date discovered</th><td class="infobox-data">12&nbsp;September 2014<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2014-09-12</span>)</span></td></tr><tr><th scope="row" class="infobox-label">Date patched</th><td class="infobox-data">24&nbsp;September 2014<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2014-09-24</span>)</span></td></tr><tr><th scope="row" class="infobox-label">Discoverer</th><td class="infobox-data">Stéphane Chazelas</td></tr><tr><th scope="row" class="infobox-label">Affected software</th><td class="infobox-data"><a href="Bash_(shell)" class="mw-redirect" title="Bash (shell)">Bash</a> (1.0.3–4.3)</td></tr></tbody></table>
<p><b>Shellshock</b>, also known as <b>Bashdoor</b>,<sup id="cite_ref-NYT-20140925-NP_1-0" class="reference"><a href="#cite_note-NYT-20140925-NP-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> is a family of <a href="Security_bug" title="Security bug">security bugs</a><sup id="cite_ref-TSM-20140927_2-0" class="reference"><a href="#cite_note-TSM-20140927-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> in the <a href="Unix" title="Unix">Unix</a> <a href="Bash_(Unix_shell)" title="Bash (Unix shell)">Bash</a> <a href="Shell_(computing)" title="Shell (computing)">shell</a>, the first of which was disclosed on 24 September 2014. Shellshock could enable an attacker to cause Bash to <a href="Arbitrary_code_execution" title="Arbitrary code execution">execute arbitrary commands</a> and gain unauthorized access<sup id="cite_ref-ZDN-20140929_3-0" class="reference"><a href="#cite_note-ZDN-20140929-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> to many Internet-facing services, such as web servers, that use Bash to process requests.
</p><p>On 12 September 2014, Stéphane Chazelas informed Bash's maintainer Chet Ramey<sup id="cite_ref-NYT-20140925-NP_1-1" class="reference"><a href="#cite_note-NYT-20140925-NP-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> of his discovery of the original bug, which he called "Bashdoor". Working with security experts, Mr. Chazelas developed a <a href="Patch_(computing)" title="Patch (computing)">patch</a><sup id="cite_ref-NYT-20140925-NP_1-2" class="reference"><a href="#cite_note-NYT-20140925-NP-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> (fix) for the issue, which by then had been assigned the vulnerability identifier <i><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6271">2014-6271</a></i>.<sup id="cite_ref-seclist-q3-650_4-0" class="reference"><a href="#cite_note-seclist-q3-650-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> The existence of the bug was announced to the public on 2014-09-24, when Bash updates with the fix were ready for distribution.<sup id="cite_ref-seclist-q3-666_5-0" class="reference"><a href="#cite_note-seclist-q3-666-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>The bug Chazelas discovered caused Bash to unintentionally execute commands when the commands are concatenated to the end of <a href="Subroutine" class="mw-redirect" title="Subroutine">function definitions</a> stored in the values of <a href="Environment_variable" title="Environment variable">environment variables</a>.<sup id="cite_ref-NYT-20140925-NP_1-3" class="reference"><a href="#cite_note-NYT-20140925-NP-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-TR-20140924_6-0" class="reference"><a href="#cite_note-TR-20140924-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Within days of its publication, a variety of related vulnerabilities were discovered (<i><a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6277">2014-6277</a>, CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6278">2014-6278</a>, CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7169">2014-7169</a>, CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7186">2014-7186</a> and CVE-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7187">2014-7187</a></i>). Ramey addressed these with a series of further patches.<sup id="cite_ref-ITN-20140929_7-0" class="reference"><a href="#cite_note-ITN-20140929-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-zdnet-betterbash_8-0" class="reference"><a href="#cite_note-zdnet-betterbash-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>Attackers exploited Shellshock within hours of the initial disclosure by creating <a href="Botnet" title="Botnet">botnets</a> of compromised computers to perform <a href="Denial-of-service_attack#Distributed_attack" title="Denial-of-service attack">distributed denial-of-service attacks</a> and <a href="Vulnerability_scanner" title="Vulnerability scanner">vulnerability scanning</a>.<sup id="cite_ref-Wired_9-0" class="reference"><a href="#cite_note-Wired-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-IT-20140926-JS_10-0" class="reference"><a href="#cite_note-IT-20140926-JS-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> Security companies recorded millions of attacks and probes related to the bug in the days following the disclosure.<sup id="cite_ref-NYT-20140926-NP_11-0" class="reference"><a href="#cite_note-NYT-20140926-NP-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-businessweek_12-0" class="reference"><a href="#cite_note-businessweek-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>Because of the potential to compromise millions of unpatched systems, Shellshock was compared to the <a href="Heartbleed" title="Heartbleed">Heartbleed</a> bug in its severity.<sup id="cite_ref-ZDN-20140929_3-1" class="reference"><a href="#cite_note-ZDN-20140929-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-mit-tech_13-0" class="reference"><a href="#cite_note-mit-tech-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Background">Background</h2></div>
<p>The Shellshock bug affects <a href="Bash_(Unix_shell)" title="Bash (Unix shell)">Bash</a>, a program that various <a href="Unix" title="Unix">Unix</a>-based systems use to execute command lines and command scripts. It is often installed as the system's default <a href="Command-line_interface" title="Command-line interface">command-line interface</a>. Analysis of the <a href="Source_code" title="Source code">source code</a> history of Bash shows the bug was introduced on 5 August 1989, and released in Bash version 1.03 on 1 September 1989.<sup id="cite_ref-BASH105_CHANGELOG_14-0" class="reference"><a href="#cite_note-BASH105_CHANGELOG-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-BASHBUG-20141010-SC_15-0" class="reference"><a href="#cite_note-BASHBUG-20141010-SC-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Stack_Exchange_Thread_16-0" class="reference"><a href="#cite_note-Stack_Exchange_Thread-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p><p>Shellshock is an <a href="Arbitrary_code_execution" title="Arbitrary code execution">arbitrary code execution</a> vulnerability that offers a way for users of a system to execute commands that should be unavailable to them. This happens through Bash's "function export" feature, whereby one Bash <a href="Process_(computing)" title="Process (computing)">process</a> can share command scripts with other Bash processes that it executes.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> This feature is implemented by encoding the scripts in a table that is shared between the processes, known as the <a href="Environment_variable" title="Environment variable">environment variable</a> list. Each new Bash process scans this table for encoded scripts, assembles each one into a command that defines that script in the new process, and executes that command.<sup id="cite_ref-exported-function_18-0" class="reference"><a href="#cite_note-exported-function-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> The new process assumes that the scripts found in the list come from another Bash process, but it cannot verify this, nor can it verify that the command that it has built is a properly formed script definition. Therefore, an attacker can execute arbitrary commands on the system or exploit other bugs that may exist in Bash's command interpreter, if the attacker has a way to manipulate the environment variable list and then cause Bash to run. At the time the bug was discovered, Bash was installed on <a href="MacOS" title="MacOS">macOS</a> and many <a href="Linux" title="Linux">Linux</a> operating systems as the main command interpreter, so that any program that used the <code>system</code> function to run any other program would use Bash to do so.
</p><p>The presence of the bug was announced to the public on 2014-09-24, when Bash updates with the fix were ready for distribution,<sup id="cite_ref-seclist-q3-666_5-1" class="reference"><a href="#cite_note-seclist-q3-666-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> though it took some time for computers to be updated to close the potential security issue.
</p>
<div class="mw-heading mw-heading2"><h2 id="Reports_of_attacks">Reports of attacks</h2></div>
<p>Within an hour of the announcement of the Bash vulnerability, there were reports of machines being compromised by the bug. By 25 September 2014, <a href="Botnet" title="Botnet">botnets</a> based on computers compromised with exploits based on the bug were being used by attackers for <a href="Denial-of-service_attack#Distributed_attack" title="Denial-of-service attack">distributed denial-of-service</a> (DDoS) attacks and <a href="Vulnerability_scanner" title="Vulnerability scanner">vulnerability scanning</a>.<sup id="cite_ref-Wired_9-1" class="reference"><a href="#cite_note-Wired-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-IT-20140926-JS_10-1" class="reference"><a href="#cite_note-IT-20140926-JS-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-bbconShellshock_19-0" class="reference"><a href="#cite_note-bbconShellshock-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> <a href="Kaspersky_Labs" class="mw-redirect" title="Kaspersky Labs">Kaspersky Labs</a> reported that machines compromised in an attack, dubbed "Thanks-Rob", were conducting DDoS attacks against three targets, which they did not identify.<sup id="cite_ref-Wired_9-2" class="reference"><a href="#cite_note-Wired-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> On 26 September 2014, a Shellshock-related botnet dubbed "wopbot" was reported, which was being used for a DDoS attack against <a href="Akamai_Technologies" title="Akamai Technologies">Akamai Technologies</a> and to scan the <a href="United_States_Department_of_Defense" title="United States Department of Defense">United States Department of Defense</a>.<sup id="cite_ref-IT-20140926-JS_10-2" class="reference"><a href="#cite_note-IT-20140926-JS-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p><p>On 26 September, the security firm <a href="Incapsula" title="Incapsula">Incapsula</a> noted 17,400 attacks on more than 1,800 web domains, originating from 400 unique IP addresses, in the previous 24 hours; 55% of the attacks were coming from China and the United States.<sup id="cite_ref-NYT-20140926-NP_11-1" class="reference"><a href="#cite_note-NYT-20140926-NP-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> By 30 September, the website performance firm <a href="CloudFlare" class="mw-redirect" title="CloudFlare">CloudFlare</a> said it was tracking approximately 1.5 million attacks and probes per day related to the bug.<sup id="cite_ref-businessweek_12-1" class="reference"><a href="#cite_note-businessweek-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>On 6 October, it was widely reported that <a href="Yahoo!" class="mw-redirect" title="Yahoo!">Yahoo!</a> servers had been compromised in an attack related to the Shellshock issue.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
Yet the next day, it was denied that it had been <i>Shellshock</i> that specifically had allowed these attacks.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Specific_exploitation_vectors">Specific exploitation vectors</h2></div>
<dl><dt>CGI-based web server</dt>
<dd>When a <a href="Web_server" title="Web server">web server</a> uses the <a href="Common_Gateway_Interface" title="Common Gateway Interface">Common Gateway Interface</a> (CGI) to handle a document request, it copies certain information from the request into the environment variable list and then delegates the request to a handler program. If the handler is a Bash script, or if it executes Bash, then Bash will receive the environment variables passed by the server and will process them as described above. This provides a means for an attacker to trigger the Shellshock vulnerability with a specially crafted document request.<sup id="cite_ref-TR-20140924_6-1" class="reference"><a href="#cite_note-TR-20140924-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup></dd>
<dd>Security documentation for the widely used <a href="Apache_HTTP_Server" title="Apache HTTP Server">Apache</a> web server states: "CGI scripts can ... be extremely dangerous if they are not carefully checked,"<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> and other methods of handling web server requests are typically used instead. There are a number of online services which attempt to test the vulnerability against web servers exposed to the Internet.</dd>
<dt>OpenSSH server</dt>
<dd><a href="OpenSSH" title="OpenSSH">OpenSSH</a> has a "ForceCommand" feature, where a fixed command is executed when the user logs in, instead of just running an unrestricted command shell. The fixed command is executed even if the user specified that another command should be run; in that case the original command is put into the environment variable "SSH_ORIGINAL_COMMAND". When the forced command is run in a Bash shell (if the user's shell is set to Bash), the Bash shell will parse the SSH_ORIGINAL_COMMAND environment variable on start-up, and run the commands embedded in it. The user has used their restricted shell access to gain unrestricted shell access, using the Shellshock bug.<sup id="cite_ref-qualys_24-0" class="reference"><a href="#cite_note-qualys-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup></dd>
<dt>DHCP clients</dt>
<dd>Some <a href="Dynamic_Host_Configuration_Protocol" title="Dynamic Host Configuration Protocol">DHCP</a> clients can also pass commands to Bash; a vulnerable system could be attacked when connecting to an open Wi-Fi network. A DHCP client typically requests and gets an IP address from a DHCP server, but it can also be provided a series of additional options. A malicious DHCP server could provide, in one of these options, a string crafted to execute code on a vulnerable workstation or laptop.<sup id="cite_ref-mit-tech_13-1" class="reference"><a href="#cite_note-mit-tech-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup></dd>
<dt>Qmail server</dt>
<dd>When using Bash to process email messages (e.g. through .forward or qmail-alias piping), the <a href="Qmail" title="Qmail">qmail</a> mail server passes external input through in a way that can exploit a vulnerable version of Bash.<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-ITN-20140929_7-1" class="reference"><a href="#cite_note-ITN-20140929-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup></dd>
<dt>IBM HMC restricted shell</dt>
<dd>The bug can be exploited to gain access to Bash from the <a href="Restricted_shell" title="Restricted shell">restricted shell</a> of the <a href="IBM_Hardware_Management_Console" title="IBM Hardware Management Console">IBM Hardware Management Console</a>,<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> a tiny Linux variant for system administrators. IBM released a patch to resolve this.<sup id="cite_ref-ibm-hmc_27-0" class="reference"><a href="#cite_note-ibm-hmc-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup></dd></dl>
<div class="mw-heading mw-heading2"><h2 id="Reported_vulnerabilities">Reported vulnerabilities</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Overview">Overview</h3></div>
<p>The maintainer of Bash was warned about the first discovery of the bug on 2014-09-12; a fix followed soon.<sup id="cite_ref-NYT-20140925-NP_1-4" class="reference"><a href="#cite_note-NYT-20140925-NP-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> A few companies and distributors were informed before the matter was publicly disclosed on 2014-09-24 with CVE identifier <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6271">2014-6271</a>.<sup id="cite_ref-seclist-q3-650_4-1" class="reference"><a href="#cite_note-seclist-q3-650-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-seclist-q3-666_5-2" class="reference"><a href="#cite_note-seclist-q3-666-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> However, after the release of the patch there were subsequent reports of different, yet related vulnerabilities.<sup id="cite_ref-wheeler-summary_28-0" class="reference"><a href="#cite_note-wheeler-summary-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup>
</p><p>On 26 September 2014, two open-source contributors, David A. Wheeler and Norihiro Tanaka, noted that there were additional issues, even after patching systems using the most recently available patches. In an email addressed to the oss-sec and bash-bug mailing lists, Wheeler wrote: "This patch just continues the <a href="Whac-a-Mole" class="mw-redirect" title="Whac-a-Mole">'whack-a-mole'</a> [<i><a href="Sic" title="Sic">sic</a></i>] job of fixing parsing errors that began with the first patch. Bash's parser is certain [to] have many many many other vulnerabilities".<sup id="cite_ref-BASH_Whack-a-mole_29-0" class="reference"><a href="#cite_note-BASH_Whack-a-mole-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
</p><p>On 27 September 2014, <a href="Micha%C5%82_Zalewski" title="Michał Zalewski">Michał Zalewski</a> from <a href="Google_Inc." class="mw-redirect" title="Google Inc.">Google Inc.</a> announced his discovery of other Bash vulnerabilities,<sup id="cite_ref-ITN-20140929_7-2" class="reference"><a href="#cite_note-ITN-20140929-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> one based upon the fact that Bash is typically compiled without <a href="Address_space_layout_randomization" title="Address space layout randomization">address space layout randomization</a>.<sup id="cite_ref-HH-20140928_30-0" class="reference"><a href="#cite_note-HH-20140928-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup> On 1 October, Zalewski released details of the final bugs and confirmed that a patch by Florian Weimer from <a href="Red_Hat" title="Red Hat">Red Hat</a> posted on 25 September does indeed prevent them. He has done that using a <a href="Fuzzing" title="Fuzzing">fuzzing</a> technique with the aid of software utility known as <i><a href="American_fuzzy_lop_(fuzzer)" class="mw-redirect" title="American fuzzy lop (fuzzer)">american fuzzy lop</a></i>.<sup id="cite_ref-lcamtuf-oct-1_31-0" class="reference"><a href="#cite_note-lcamtuf-oct-1-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Initial_report_(CVE-2014-6271)">Initial report (CVE-2014-6271)</h3></div>
<p>This original form of the vulnerability (<a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6271">2014-6271</a>) involves a specially crafted environment variable containing an exported function definition, followed by arbitrary commands. Bash incorrectly executes the trailing commands when it imports the function.<sup id="cite_ref-nvd6271_32-0" class="reference"><a href="#cite_note-nvd6271-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> The vulnerability can be tested with the following command:
</p>
<div class="mw-highlight mw-highlight-lang-bash mw-content-ltr" dir="ltr"><pre>env<span class="w"> </span><span class="nv">x</span><span class="o">=</span><span class="s1">'() {&nbsp;:;}; echo vulnerable'</span><span class="w"> </span>bash<span class="w"> </span>-c<span class="w"> </span><span class="s2">"echo this is a test"</span>
</pre></div>
<p>In systems affected by the vulnerability, the above commands will display the word "vulnerable" as a result of Bash executing the command <i><b>"echo&nbsp;vulnerable"</b></i>, which was embedded into the specially crafted environment variable named <i><b>"x"</b></i>.<sup id="cite_ref-zdnet-betterbash_8-1" class="reference"><a href="#cite_note-zdnet-betterbash-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="CVE-2014-6277">CVE-2014-6277</h3></div>
<p>Discovered by <a href="Micha%C5%82_Zalewski" title="Michał Zalewski">Michał Zalewski</a>,<sup id="cite_ref-ITN-20140929_7-3" class="reference"><a href="#cite_note-ITN-20140929-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-HH-20140928_30-1" class="reference"><a href="#cite_note-HH-20140928-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-NIST-20140927_34-0" class="reference"><a href="#cite_note-NIST-20140927-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> the vulnerability <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6277">2014-6277</a>, which relates to the parsing of function definitions in environment variables by Bash, can cause a <a href="Segmentation_fault" title="Segmentation fault">segfault</a>.<sup id="cite_ref-PCW-20140929_35-0" class="reference"><a href="#cite_note-PCW-20140929-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="CVE-2014-6278">CVE-2014-6278</h3></div>
<p>Also discovered by <a href="Micha%C5%82_Zalewski" title="Michał Zalewski">Michał Zalewski</a>,<sup id="cite_ref-PCW-20140929_35-1" class="reference"><a href="#cite_note-PCW-20140929-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> this bug (<a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-6278">2014-6278</a>) relates to the parsing of function definitions in environment variables by Bash.
</p>
<div class="mw-heading mw-heading3"><h3 id="CVE-2014-7169">CVE-2014-7169</h3></div>
<p>On the same day the original vulnerability was published, <a href="Tavis_Ormandy" title="Tavis Ormandy">Tavis Ormandy</a> discovered this related bug (<a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7169">2014-7169</a>),<sup id="cite_ref-qualys_24-1" class="reference"><a href="#cite_note-qualys-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup> which is
demonstrated in the following code:
</p>
<div class="mw-highlight mw-highlight-lang-bash mw-content-ltr" dir="ltr"><pre>env<span class="w"> </span><span class="nv">X</span><span class="o">=</span><span class="s1">'() { (a)=&gt;\'</span><span class="w"> </span>bash<span class="w"> </span>-c<span class="w"> </span><span class="s2">"echo date"</span><span class="p">;</span><span class="w"> </span>cat<span class="w"> </span><span class="nb">echo</span>
</pre></div>
<p>On a vulnerable system, this would execute the command "date" unintentionally.<sup id="cite_ref-qualys_24-2" class="reference"><a href="#cite_note-qualys-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p><p>Here is an example of a system that has a patch for CVE-2014-6271 but not CVE-2014-7169:
</p>
<div class="mw-highlight mw-highlight-lang-console mw-content-ltr" dir="ltr"><pre><span class="gp">$ </span><span class="nv">X</span><span class="o">=</span><span class="s1">'() { (a)=&gt;\'</span><span class="w"> </span>bash<span class="w"> </span>-c<span class="w"> </span><span class="s2">"echo date"</span>
<span class="go">bash: X: line 1: syntax error near unexpected token `='</span>
<span class="go">bash: X: line 1: `'</span>
<span class="go">bash: error importing function definition for `X'</span>
<span class="gp">$ </span>cat<span class="w"> </span><span class="nb">echo</span>
<span class="go">Fri Sep 26 01:37:16 UTC 2014</span>
</pre></div>
<p>The system displays syntax errors, notifying the user that CVE-2014-6271 has been prevented, but still writes a file named 'echo', into the working directory, containing the result of the 'date' call.
</p><p>A system patched for both CVE-2014-6271 and CVE-2014-7169 will simply echo the word "date" and the file "echo" will <i>not</i> be created, as shown below:
</p>
<div class="mw-highlight mw-highlight-lang-console mw-content-ltr" dir="ltr"><pre><span class="gp">$ </span><span class="nv">X</span><span class="o">=</span><span class="s1">'() { (a)=&gt;\'</span><span class="w"> </span>bash<span class="w"> </span>-c<span class="w"> </span><span class="s2">"echo date"</span>
<span class="go">date</span>
<span class="gp">$ </span>cat<span class="w"> </span><span class="nb">echo</span>
<span class="go">cat: echo: No such file or directory</span>
</pre></div>
<div class="mw-heading mw-heading3"><h3 id="CVE-2014-7186">CVE-2014-7186</h3></div>
<p>Florian Weimer and Todd Sabin found this bug (<a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7186">2014-7186</a>),<sup id="cite_ref-zdnet-betterbash_8-2" class="reference"><a href="#cite_note-zdnet-betterbash-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-lcamtuf-oct-1_31-1" class="reference"><a href="#cite_note-lcamtuf-oct-1-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> which relates to an <a href="Buffer_overflow" title="Buffer overflow">out-of-bounds memory access error</a> in the Bash parser code.<sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup>
</p><p>An example of the vulnerability, which leverages the use of multiple "&lt;&lt;EOF" declarations (nested <a href="Here_document" title="Here document">"here documents"</a>):
</p>
<div class="mw-highlight mw-highlight-lang-bash mw-content-ltr" dir="ltr"><pre>bash<span class="w"> </span>-c<span class="w"> </span><span class="s1">'true &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF &lt;&lt;EOF'</span><span class="w"> </span><span class="o">||</span>
<span class="nb">echo</span><span class="w"> </span><span class="s2">"CVE-2014-7186 vulnerable, redir_stack"</span>
</pre></div>
<p>A vulnerable system will echo the text "CVE-2014-7186 vulnerable, redir_stack".
</p>
<div class="mw-heading mw-heading3"><h3 id="CVE-2014-7187">CVE-2014-7187</h3></div>
<p>Also found by Florian Weimer,<sup id="cite_ref-zdnet-betterbash_8-3" class="reference"><a href="#cite_note-zdnet-betterbash-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> <a href="CVE_(identifier)" class="mw-redirect" title="CVE (identifier)">CVE</a>-<a rel="nofollow" class="external text" href="https://nvd.nist.gov/vuln/detail/CVE-2014-7187">2014-7187</a> is an <a href="Off-by-one_error" title="Off-by-one error">off-by-one error</a> in the Bash parser code, allowing out-of-bounds memory access.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup>
</p><p>An example of the vulnerability, which leverages the use of multiple "done" declarations:
</p>
<div class="mw-highlight mw-highlight-lang-bash mw-content-ltr" dir="ltr"><pre><span class="o">(</span><span class="k">for</span><span class="w"> </span>x<span class="w"> </span><span class="k">in</span><span class="w"> </span><span class="o">{</span><span class="m">1</span>..200<span class="o">}</span><span class="w"> </span><span class="p">;</span><span class="w"> </span><span class="k">do</span><span class="w"> </span><span class="nb">echo</span><span class="w"> </span><span class="s2">"for x</span><span class="nv">$x</span><span class="s2"> in&nbsp;; do&nbsp;:"</span><span class="p">;</span><span class="w"> </span><span class="k">done</span><span class="p">;</span><span class="w"> </span><span class="k">for</span><span class="w"> </span>x<span class="w"> </span><span class="k">in</span><span class="w"> </span><span class="o">{</span><span class="m">1</span>..200<span class="o">}</span><span class="w"> </span><span class="p">;</span><span class="w"> </span><span class="k">do</span><span class="w"> </span><span class="nb">echo</span><span class="w"> </span><span class="k">done</span><span class="w"> </span><span class="p">;</span><span class="w"> </span><span class="k">done</span><span class="o">)</span><span class="w"> </span><span class="p">|</span><span class="w"> </span>bash<span class="w"> </span><span class="o">||</span>
<span class="nb">echo</span><span class="w"> </span><span class="s2">"CVE-2014-7187 vulnerable, word_lineno"</span>
</pre></div>
<p>A vulnerable system will echo the text "CVE-2014-7187 vulnerable, word_lineno". This test requires a shell that supports <a href="Brace_expansion" class="mw-redirect" title="Brace expansion">brace expansion</a>.<sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Patches">Patches</h2></div>
<p>Until 24 September 2014, Bash maintainer Chet Ramey provided a patch version bash43-025 of Bash 4.3 addressing CVE-2014-6271,<sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup> which was already packaged by distribution maintainers. On 24 September, bash43-026 followed, addressing CVE-2014-7169.<sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup>
Then CVE-2014-7186 was discovered. Florian Weimer from <a href="Red_Hat" title="Red Hat">Red Hat</a> posted some patch code for this "unofficially" on 25 September,<sup id="cite_ref-42" class="reference"><a href="#cite_note-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup>
which Ramey incorporated into Bash as bash43-027.<sup id="cite_ref-43" class="reference"><a href="#cite_note-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-44" class="reference"><a href="#cite_note-44"><span class="cite-bracket">[</span>44<span class="cite-bracket">]</span></a></sup>—These patches provided <i>source code</i> only, helpful only for those who know how to <a href="Compile" class="mw-redirect" title="Compile">compile</a> ("<a href="Software_build" title="Software build">rebuild</a>") a new Bash <a href="Binary_executable" class="mw-redirect" title="Binary executable">binary executable</a> file from the patch file and remaining source code files. The patches added a variable name prefix when functions are exported; this prevented arbitrary variables from triggering the vulnerability and enabled other programs to remove Bash functions from the environment.
</p><p>The next day, Red Hat officially presented according updates for <a href="Red_Hat_Enterprise_Linux" title="Red Hat Enterprise Linux">Red Hat Enterprise Linux</a>,<sup id="cite_ref-45" class="reference"><a href="#cite_note-45"><span class="cite-bracket">[</span>45<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-rh-art_46-0" class="reference"><a href="#cite_note-rh-art-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup> after another day for <a href="Fedora_(operating_system)" class="mw-redirect" title="Fedora (operating system)">Fedora 21</a>.<sup id="cite_ref-47" class="reference"><a href="#cite_note-47"><span class="cite-bracket">[</span>47<span class="cite-bracket">]</span></a></sup>
<a href="Canonical_Ltd." class="mw-redirect" title="Canonical Ltd.">Canonical Ltd.</a> presented updates for its <a href="Ubuntu_(operating_system)" class="mw-redirect" title="Ubuntu (operating system)">Ubuntu</a> <i>Long Term Support</i> versions on Saturday, 27 September;<sup id="cite_ref-48" class="reference"><a href="#cite_note-48"><span class="cite-bracket">[</span>48<span class="cite-bracket">]</span></a></sup>
on Sunday, there were updates for <a href="SUSE_Linux_Enterprise" title="SUSE Linux Enterprise">SUSE Linux Enterprise</a>.<sup id="cite_ref-49" class="reference"><a href="#cite_note-49"><span class="cite-bracket">[</span>49<span class="cite-bracket">]</span></a></sup>
The following Monday and Tuesday at the end of the month, <a href="MacOS" title="MacOS">Mac OS X</a> updates appeared.<sup id="cite_ref-50" class="reference"><a href="#cite_note-50"><span class="cite-bracket">[</span>50<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-51" class="reference"><a href="#cite_note-51"><span class="cite-bracket">[</span>51<span class="cite-bracket">]</span></a></sup>
</p><p>On 1 October 2014, <a href="Micha%C5%82_Zalewski" title="Michał Zalewski">Michał Zalewski</a> from <a href="Google_Inc." class="mw-redirect" title="Google Inc.">Google Inc.</a> finally stated that Weimer's code and bash43-027 had fixed not only the first three bugs but even the remaining three that were published after bash43-027, including his own two discoveries.<sup id="cite_ref-lcamtuf-oct-1_31-2" class="reference"><a href="#cite_note-lcamtuf-oct-1-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> This means that after the earlier distribution updates, no other updates have been required to cover all the six issues.<sup id="cite_ref-rh-art_46-1" class="reference"><a href="#cite_note-rh-art-46"><span class="cite-bracket">[</span>46<span class="cite-bracket">]</span></a></sup>
</p><p>All of them have also been covered for the <a href="#Specific_exploitation_vectors">IBM <i>Hardware Management Console</i></a>.<sup id="cite_ref-ibm-hmc_27-1" class="reference"><a href="#cite_note-ibm-hmc-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-NYT-20140925-NP-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-NYT-20140925-NP_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-NYT-20140925-NP_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-NYT-20140925-NP_1-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-NYT-20140925-NP_1-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-NYT-20140925-NP_1-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFPerlroth2014" class="citation news cs1">Perlroth, Nicole (25 September 2014). <a rel="nofollow" class="external text" href="https://www.nytimes.com/2014/09/26/technology/security-experts-expect-shellshock-software-bug-to-be-significant.html">"Security Experts Expect 'Shellshock' Software Bug in Bash to Be Significant"</a>. <i><a href="New_York_Times" class="mw-redirect" title="New York Times">New York Times</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">25 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-TSM-20140927-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-TSM-20140927_2-0">^</a></b></span> <span class="reference-text">Although described in some sources as a "virus," Shellshock is instead a design flaw in a program that comes with some operating systems. See =&gt; <cite id="CITEREFStaff2014" class="citation web cs1">Staff (25 September 2014). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20140929053202/http://www.thesafemac.com/what-does-the-shellshock-bug-affect/">"What does the "Shellshock" bug affect?"</a>. <i>The Safe Mac</i>. Archived from <a rel="nofollow" class="external text" href="http://www.thesafemac.com/what-does-the-shellshock-bug-affect/">the original</a> on 29 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">27 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-ZDN-20140929-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-ZDN-20140929_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ZDN-20140929_3-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFSeltzer2014" class="citation web cs1">Seltzer, Larry (29 September 2014). <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/shellshock-makes-heartbleed-look-insignificant/">"Shellshock makes Heartbleed look insignificant"</a>. <i><a href="ZDNet" class="mw-redirect" title="ZDNet">ZDNet</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">29 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-seclist-q3-650-4"><span class="mw-cite-backlink">^ <a href="#cite_ref-seclist-q3-650_4-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-seclist-q3-650_4-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFFlorian_Weimer2014" class="citation mailinglist cs1">Florian Weimer (24 September 2014). <a rel="nofollow" class="external text" href="http://seclists.org/oss-sec/2014/q3/650">"Re: CVE-2014-6271: remote code execution through bash"</a>. <i>oss-sec</i> (Mailing list)<span class="reference-accessdate">. Retrieved <span class="nowrap">1 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-seclist-q3-666-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-seclist-q3-666_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-seclist-q3-666_5-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-seclist-q3-666_5-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFFlorian_Weimer2014" class="citation mailinglist cs1">Florian Weimer (24 September 2014). <a rel="nofollow" class="external text" href="http://seclists.org/oss-sec/2014/q3/666">"Re: CVE-2014-6271: remote code execution through bash"</a>. <i>oss-sec</i> (Mailing list)<span class="reference-accessdate">. Retrieved <span class="nowrap">1 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-TR-20140924-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-TR-20140924_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-TR-20140924_6-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFLeyden2014" class="citation web cs1">Leyden, John (24 September 2014). <a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2014/09/24/bash_shell_vuln/">"Patch Bash NOW: 'Shell Shock' bug blasts OS X, Linux systems wide open"</a>. <i><a href="The_Register" title="The Register">The Register</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">25 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-ITN-20140929-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-ITN-20140929_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ITN-20140929_7-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-ITN-20140929_7-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-ITN-20140929_7-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFSaarinen2014" class="citation web cs1">Saarinen, Juha (29 September 2014). <a rel="nofollow" class="external text" href="http://www.itnews.com.au/News/396256,further-flaws-render-shellshock-patch-ineffective.aspx">"Further flaws render Shellshock patch ineffective"</a>. <i>iTnews</i><span class="reference-accessdate">. Retrieved <span class="nowrap">29 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-zdnet-betterbash-8"><span class="mw-cite-backlink">^ <a href="#cite_ref-zdnet-betterbash_8-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-zdnet-betterbash_8-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-zdnet-betterbash_8-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-zdnet-betterbash_8-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFVaughan-Nichols2014" class="citation web cs1">Vaughan-Nichols, Steven (27 September 2014). <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/shellshock-better-bash-patches-now-available/">"Shellshock: Better 'bash' patches now available"</a>. ZDNet<span class="reference-accessdate">. Retrieved <span class="nowrap">29 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-Wired-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-Wired_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Wired_9-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Wired_9-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGreenberg2014" class="citation magazine cs1">Greenberg, Andy (25 September 2014). <a rel="nofollow" class="external text" href="https://www.wired.com/2014/09/hackers-already-using-shellshock-bug-create-botnets-ddos-attacks/">"Hackers Are Already Using the Shellshock Bug to Launch Botnet Attacks"</a>. <i>Wired</i><span class="reference-accessdate">. Retrieved <span class="nowrap">28 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-IT-20140926-JS-10"><span class="mw-cite-backlink">^ <a href="#cite_ref-IT-20140926-JS_10-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-IT-20140926-JS_10-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-IT-20140926-JS_10-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFSaarinen2014" class="citation news cs1">Saarinen, Juha (26 September 2014). <a rel="nofollow" class="external text" href="http://www.itnews.com.au/News/396197,first-shellshock-botnet-attacks-akamai-us-dod-networks.aspx">"First Shellshock botnet attacks Akamai, US DoD networks"</a>. <i>iTnews</i><span class="reference-accessdate">. Retrieved <span class="nowrap">26 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-NYT-20140926-NP-11"><span class="mw-cite-backlink">^ <a href="#cite_ref-NYT-20140926-NP_11-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-NYT-20140926-NP_11-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFPerlroth2014" class="citation news cs1">Perlroth, Nicole (26 September 2014). <a rel="nofollow" class="external text" href="https://bits.blogs.nytimes.com/2014/09/26/companies-rush-to-fix-shellshock-software-bug-as-hackers-launch-thousands-of-attacks/">"Companies Rush to Fix Shellshock Software Bug as Hackers Launch Thousands of Attacks"</a>. <i><a href="New_York_Times" class="mw-redirect" title="New York Times">New York Times</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">29 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-businessweek-12"><span class="mw-cite-backlink">^ <a href="#cite_ref-businessweek_12-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-businessweek_12-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFStrohmRobertson2014" class="citation web cs1">Strohm, Chris; Robertson, Jordan (30 September 2014). <a rel="nofollow" class="external text" href="https://archive.today/20141001033848/http://www.businessweek.com/news/2014-09-30/shellshock-draws-hacker-attacks-sparks-race-to-patch-bug">"Shellshock Draws Hacker Attacks, Sparks Race to Patch Bug"</a>. Businessweek. Archived from <a rel="nofollow" class="external text" href="http://www.businessweek.com/news/2014-09-30/shellshock-draws-hacker-attacks-sparks-race-to-patch-bug">the original</a> on 1 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-mit-tech-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-mit-tech_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-mit-tech_13-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFCerrudo2014" class="citation web cs1">Cerrudo, Cesar (30 September 2014). <a rel="nofollow" class="external text" href="http://www.technologyreview.com/view/531286/why-the-shellshock-bug-is-worse-than-heartbleed/">"Why the Shellshock Bug Is Worse than Heartbleed"</a>. <i><a href="MIT_Technology_Review" title="MIT Technology Review">MIT Technology Review</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-BASH105_CHANGELOG-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-BASH105_CHANGELOG_14-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFFox1990" class="citation web cs1">Fox, Brian (21 March 1990). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20231206061143/http://www.oldlinux.org/Linux.old/bin/old/bash-1.05/ChangeLog">"Bash 1.05 ChangeLog"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.oldlinux.org/Linux.old/bin/old/bash-1.05/ChangeLog">the original</a> on 6 December 2023<span class="reference-accessdate">. Retrieved <span class="nowrap">14 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-BASHBUG-20141010-SC-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-BASHBUG-20141010-SC_15-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFChazelas2014" class="citation web cs1">Chazelas, Stéphane (10 October 2014). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20161220033324/http://thread.gmane.org/gmane.comp.shells.bash.bugs/22418">"when was shellshock introduced"</a>. <i>Stéphane Chazelas and Chet Ramey confirm the vulnerability introduction date on Bash official communication channel</i>. Archived from <a rel="nofollow" class="external text" href="http://thread.gmane.org/gmane.comp.shells.bash.bugs/22418">the original</a> on 20 December 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">14 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-Stack_Exchange_Thread-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-Stack_Exchange_Thread_16-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFChazelas2014" class="citation web cs1">Chazelas, Stéphane (25 September 2014). <a rel="nofollow" class="external text" href="https://unix.stackexchange.com/questions/157381/when-was-the-shellshock-cve-2014-6271-7169-bug-introduced-and-what-is-the-pat/157495#157495">"When was the shellshock (CVE-2014-6271/7169) bug introduced, and what is the patch that fully fixes it?"</a>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.gnu.org/software/bash/manual/bash.html#Shell-Functions">"Bash Reference Manual: Shell Functions"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-exported-function-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-exported-function_18-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://git.savannah.gnu.org/cgit/bash.git/tree/variables.c?id=ac50fbac377e32b98d2de396f016ea81e8ee9961#n315">"Bash 4.3 source code, file variables.c, lines 315-388"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-bbconShellshock-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-bbconShellshock_19-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFVarious2014" class="citation web cs1">Various (26 September 2014). <a rel="nofollow" class="external text" href="https://www.bbc.com/news/technology-29375636">"Web attacks build on Shellshock bug"</a>. <i><a href="BBC" title="BBC">BBC</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">26 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite id="CITEREFBoren2014" class="citation news cs1">Boren, Zachary (6 October 2014). <a rel="nofollow" class="external text" href="https://www.independent.co.uk/life-style/gadgets-and-tech/news/shellshock-romanian-hackers-are-accessing-yahoo-servers-claims-security-expert-9777753.html">"Shellshock: Romanian hackers are accessing Yahoo servers, claims security expert"</a>. <i>Independent</i><span class="reference-accessdate">. Retrieved <span class="nowrap">7 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20141009075833/http://www.futuresouth.us/wordpress/?p=5">"Yahoo! Shellshocked Like Ninja Turtles!"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.futuresouth.us/wordpress/?p=5">the original</a> on 9 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">7 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite id="CITEREFHanno_Böck2014" class="citation web cs1 cs1-prop-foreign-lang-source">Hanno Böck (7 October 2014). <a rel="nofollow" class="external text" href="http://www.golem.de/news/bash-luecke-yahoo-durch-shellshock-angegriffen-1410-109656.html">"Yahoo durch Shellshock angegriffen"</a>. <i>Golem - IT-News für Profis</i> (in German)<span class="reference-accessdate">. Retrieved <span class="nowrap">30 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://httpd.apache.org/docs/2.2/misc/security_tips.html">"Apache HTTP Server 2.2 Documentation: Security Tips"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-qualys-24"><span class="mw-cite-backlink">^ <a href="#cite_ref-qualys_24-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-qualys_24-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-qualys_24-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWolfgang_Kandek2014" class="citation web cs1">Wolfgang Kandek (24 September 2014). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160503034655/https://blog.qualys.com/laws-of-vulnerabilities/2014/09/24/bash-shellshock-vulnerability">"The Laws of Vulnerabilities"</a>. Qualys.com. Archived from <a rel="nofollow" class="external text" href="https://blog.qualys.com/laws-of-vulnerabilities/2014/09/24/bash-shellshock-vulnerability">the original</a> on 3 May 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">26 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite id="CITEREFKyle_George2014" class="citation mailinglist cs1">Kyle George (27 September 2014). <a rel="nofollow" class="external text" href="https://lists.archive.carbon60.com/qmail/users/138578">"qmail is a vector for CVE-2014-6271 (bash shellshock)"</a>. <i>qmail</i> (Mailing list).</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20200119235509/https://www.ibm.com/developerworks/community/blogs/brian/resource/BLOGS_UPLOADED_IMAGES/shellshock.png">"IBM HMC is a vector for CVE-2014-6271 (bash "shellshock")"</a>. <i><a href="IBM" title="IBM">IBM</a></i>. Archived from <a rel="nofollow" class="external text" href="https://www.ibm.com/developerworks/community/blogs/brian/resource/BLOGS_UPLOADED_IMAGES/shellshock.png">the original</a> on 19 January 2020.</cite></span>
</li>
<li id="cite_note-ibm-hmc-27"><span class="mw-cite-backlink">^ <a href="#cite_ref-ibm-hmc_27-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ibm-hmc_27-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www-304.ibm.com/support/docview.wss?uid=ssg1S1004879">"Security Bulletin: Vulnerabilities in Bash affect DS8000 HMC (CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, CVE-2014-6278)"</a>. IBM. 3 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-wheeler-summary-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-wheeler-summary_28-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.dwheeler.com/essays/shellshock.html">"Shellshock"</a>. 13 February 2015<span class="reference-accessdate">. Retrieved <span class="nowrap">17 September</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-BASH_Whack-a-mole-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-BASH_Whack-a-mole_29-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFGallagher2014" class="citation web cs1">Gallagher, Sean (26 September 2014). <a rel="nofollow" class="external text" href="https://arstechnica.com/security/2014/09/still-more-vulnerabilities-in-bash-shellshock-becomes-whack-a-mole/">"Still more vulnerabilities in bash? Shellshock becomes whack-a-mole"</a>. <a href="Arstechnica" class="mw-redirect" title="Arstechnica">Arstechnica</a><span class="reference-accessdate">. Retrieved <span class="nowrap">26 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-HH-20140928-30"><span class="mw-cite-backlink">^ <a href="#cite_ref-HH-20140928_30-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-HH-20140928_30-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFStaff2014" class="citation web cs1">Staff (28 September 2014). <a rel="nofollow" class="external text" href="http://www.heise.de/security/meldung/ShellShock-Teil-3-Noch-drei-Sicherheitsprobleme-bei-der-Bash-2404788.html">"Shellshock, Part 3: Three more security problems in Bash (in german)"</a>. <i><a href="Heise_Online" class="mw-redirect" title="Heise Online">Heise Online</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">28 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-lcamtuf-oct-1-31"><span class="mw-cite-backlink">^ <a href="#cite_ref-lcamtuf-oct-1_31-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-lcamtuf-oct-1_31-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-lcamtuf-oct-1_31-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html">"Bash bug: the other two RCEs, or how we chipped away at the original fix (CVE-2014-6277 and '78)"</a>. <i>lcamtuf blog</i>. 1 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">8 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-nvd6271-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-nvd6271_32-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271">"Vulnerability Summary for CVE-2014-6271"</a>. NIST. 4 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">8 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/">"Bash specially-crafted environment variables code injection attack"</a>. <i>Red Hat Security</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-NIST-20140927-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-NIST-20140927_34-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFStaff2014" class="citation web cs1">Staff (27 September 2014). <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6277">"National Cyber Awareness System Vulnerability Summary for CVE-2014-6277"</a>. <i><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">28 September</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-PCW-20140929-35"><span class="mw-cite-backlink">^ <a href="#cite_ref-PCW-20140929_35-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-PCW-20140929_35-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFConstatin2014" class="citation web cs1">Constatin, Lucian (29 September 2014). <a rel="nofollow" class="external text" href="http://www.pcworld.com/article/2688932/improved-patch-tackles-new-shellshock-attack-vectors.html">"Improved patch tackles new Shellshock Bash bug attack vectors"</a>. <i><a href="PC_World" title="PC World">PC World</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><cite id="CITEREFStaff2014" class="citation web cs1">Staff (30 September 2014). <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6278">"National Cyber Awareness System Vulnerability Summary for CVE-2014-6278"</a>. <i><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite id="CITEREFStaff2014" class="citation web cs1">Staff (29 September 2014). <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7186">"National Cyber Awareness System Vulnerability Summary for CVE-2014-7186"</a>. <i><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite id="CITEREFStaff2014" class="citation web cs1">Staff (29 September 2014). <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7187">"National Cyber Awareness System Vulnerability Summary for CVE-2014-7187"</a>. <i><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text"><cite id="CITEREFRamey" class="citation web cs1">Ramey, Chet. <a rel="nofollow" class="external text" href="http://lists.gnu.org/archive/html/bug-bash/2014-10/msg00139.html">"Re: CVE-2014-7187"</a>. <i>lists.gnu.org</i>.</cite></span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-025">"BASH PATCH REPORT"</a>. <i><a href="GNU.org" class="mw-redirect" title="GNU.org">GNU.org</a></i>. 12 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-026">"BASH PATCH REPORT"</a>. <i><a href="GNU.org" class="mw-redirect" title="GNU.org">GNU.org</a></i>. 25 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-42">^</a></b></span> <span class="reference-text"><cite id="CITEREFWeimer2014" class="citation web cs1">Weimer, Florian (25 September 2014). <a rel="nofollow" class="external text" href="http://www.openwall.com/lists/oss-security/2014/09/25/13">"Re: CVE-2014-6271: remote code execution through bash"</a>. <i><a href="Openwall_Project" title="Openwall Project">Openwall Project</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-43">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-027">"BASH PATCH REPORT"</a>. <i><a href="GNU.org" class="mw-redirect" title="GNU.org">GNU.org</a></i>. 25 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-44"><span class="mw-cite-backlink"><b><a href="#cite_ref-44">^</a></b></span> <span class="reference-text"><cite id="CITEREFGallagher2014" class="citation web cs1">Gallagher, Sean (26 September 2014). <a rel="nofollow" class="external text" href="https://arstechnica.com/security/2014/09/new-shellshock-patch-rushed-out-to-resolve-gaps-in-first-fix/">"New "Shellshock" patch rushed out to resolve gaps in first fix [Updated]"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-45"><span class="mw-cite-backlink"><b><a href="#cite_ref-45">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://rhn.redhat.com/errata/RHSA-2014-1306.html">"Important: bash security update"</a>. Red Hat. 30 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-rh-art-46"><span class="mw-cite-backlink">^ <a href="#cite_ref-rh-art_46-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-rh-art_46-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://access.redhat.com/articles/1200223">"Bash Code Injection Vulnerability via Specially Crafted Environment Variables (CVE-2014-6271, CVE-2014-7169)"</a>. Red Hat. 2 October 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-47"><span class="mw-cite-backlink"><b><a href="#cite_ref-47">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://lists.fedoraproject.org/pipermail/package-announce/2014-September/139129.html">"[SECURITY] Fedora 21 Update: bash-4.3.25-2.fc21"</a>. <i>FedoraProject.org</i>. 27 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-48"><span class="mw-cite-backlink"><b><a href="#cite_ref-48">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.ubuntu.com/usn/usn-2364-1/">"USN-2364-1: Bash vulnerabilities"</a>. Canonical Ltd. 27 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-49"><span class="mw-cite-backlink"><b><a href="#cite_ref-49">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html">"SUSE Security Update: Security update for bash"</a>. <a href="OpenSUSE" title="OpenSUSE">OpenSUSE</a>. 28 September 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">2 November</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-50"><span class="mw-cite-backlink"><b><a href="#cite_ref-50">^</a></b></span> <span class="reference-text"><cite id="CITEREFClover2014" class="citation web cs1">Clover, Juli (29 September 2014). <a rel="nofollow" class="external text" href="http://www.macrumors.com/2014/09/29/apple-os-x-mavericks-bash-update/">"Apple Releases OS X Bash Update to Fix 'Shellshock' Security Flaw in Mavericks, Mountain Lion, and Lion"</a>. <i>MacRumors.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
<li id="cite_note-51"><span class="mw-cite-backlink"><b><a href="#cite_ref-51">^</a></b></span> <span class="reference-text"><cite id="CITEREFSlivka2014" class="citation web cs1">Slivka, Eric (30 September 2014). <a rel="nofollow" class="external text" href="http://www.macrumors.com/2014/09/30/os-x-yosemite-developer-preview-9/">"Apple Releases OS X Yosemite Golden Master Candidate to Developers [Update: Also Public Beta]"</a>. <i>MacRumors.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2014</span>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1290876196">
/* start https://en.wikipedia.org/ */


.mw-parser-output .side-box{margin:4px 0;box-sizing:border-box;border:1px solid #aaa;font-size:88%;line-height:1.25em;background-color:var(--background-color-interactive-subtle,#f8f9fa);display:flow-root}.mw-parser-output .infobox .side-box{font-size:100%}.mw-parser-output .side-box-abovebelow,.mw-parser-output .side-box-text{padding:0.25em 0.9em}.mw-parser-output .side-box-image{padding:2px 0 2px 0.9em;text-align:center}.mw-parser-output .side-box-imageright{padding:2px 0.9em 2px 0;text-align:center}@media(min-width:500px){.mw-parser-output .side-box-flex{display:flex;align-items:center}.mw-parser-output .side-box-text{flex:1;min-width:0}}@media(min-width:720px){.mw-parser-output .side-box{width:238px}.mw-parser-output .side-box-right{clear:right;float:right;margin-left:1em}.mw-parser-output .side-box-left{margin-right:1em}}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1237033735">
/* start https://en.wikipedia.org/ */


@media print{body.ns-0 .mw-parser-output .sistersitebox{display:none!important}}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}


/* end https://en.wikipedia.org/ */
</style><div class="side-box side-box-right sistersitebox"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */


.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}


/* end https://en.wikipedia.org/ */
</style>
<div class="side-box-flex">
<div class="side-box-image"><span class="noviewer" typeof="mw:File"></span></div>
<div class="side-box-text plainlist">Wikimedia Commons has media related to <span style="font-weight: bold; font-style: italic;"><a href="https://commons.wikimedia.org/wiki/Category:Shellshock_(software_bug)" class="extiw external" title="commons:Category:Shellshock (software bug)">Shellshock (software bug)</a></span>.</div></div>
</div>
<style data-mw-deduplicate="TemplateStyles:r1266661725">
/* start https://en.wikipedia.org/ */


.mw-parser-output .portalbox{padding:0;margin:0.5em 0;display:table;box-sizing:border-box;max-width:175px;list-style:none}.mw-parser-output .portalborder{border:1px solid var(--border-color-base,#a2a9b1);padding:0.1em;background:var(--background-color-neutral-subtle,#f8f9fa)}.mw-parser-output .portalbox-entry{display:table-row;font-size:85%;line-height:110%;height:1.9em;font-style:italic;font-weight:bold}.mw-parser-output .portalbox-image{display:table-cell;padding:0.2em;vertical-align:middle;text-align:center}.mw-parser-output .portalbox-link{display:table-cell;padding:0.2em 0.2em 0.2em 0.3em;vertical-align:middle}@media(min-width:720px){.mw-parser-output .portalleft{margin:0.5em 1em 0.5em 0}.mw-parser-output .portalright{clear:right;float:right;margin:0.5em 0 0.5em 1em}}


/* end https://en.wikipedia.org/ */
</style>
<ul><li><a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">NIST</a> <a rel="nofollow" class="external text" href="http://nvd.nist.gov/home.cfm">National Vulnerability Database</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110925095556/http://nvd.nist.gov/home.cfm">Archived</a> 25 September 2011 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a> &amp; <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">CVE</a> <a rel="nofollow" class="external text" href="http://cve.mitre.org">Common Vulnerabilities and Exposures</a>
<ul><li>CVE-2014-6271 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271">20140924nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271">20140909cve</a> (first bug)</li>
<li>CVE-2014-6277 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6277">20140927nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6277">20140909cve</a></li>
<li>CVE-2014-6278 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6278">20140930nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6278">20140909cve</a></li>
<li>CVE-2014-7169 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169">20140924nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7169">20140924cve</a> (second bug)</li>
<li>CVE-2014-7186 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7186">20140929nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186">20140925cve</a></li>
<li>CVE-2014-7187 - <a rel="nofollow" class="external text" href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7187">20140929nist</a> &amp; <a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187">20140925cve</a></li></ul></li>
<li><a rel="nofollow" class="external text" href="https://ftp.gnu.org/gnu/bash/">Bash source code</a> from the <a href="GNU_Project" title="GNU Project">GNU Project</a>, includes patches for known vulnerabilities (28 September 2014)</li>
<li><a rel="nofollow" class="external text" href="https://www.fireeye.com/blog/threat-research/2014/09/shellshock-in-the-wild.html">"Shellshock in the Wild", Malware droppers, Reverse shells &amp; backdoors, Data exfiltration, and DDoS</a> at <a href="FireEye%2C_Inc." class="mw-redirect" title="FireEye, Inc.">FireEye, Inc.</a></li>
<li><a rel="nofollow" class="external text" href="https://isc.sans.edu/diary/Shellshock%3A+A+Collection+of+Exploits+seen+in+the+wild/18725">Collection of attacks seen in the wild (29 September 2014)</a> at <a href="SANS_Institute" title="SANS Institute">SANS Institute</a></li>
<li><a rel="nofollow" class="external text" href="http://www.oracle.com/technetwork/topics/security/alert-cve-2014-7169-2303276.html">Security Alert for CVE-2014-7169</a> at <a href="Oracle_Corporation" title="Oracle Corporation">Oracle</a></li>
<li><a rel="nofollow" class="external text" href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=2090740">"VMware remediation of Bash Code Injection Vulnerability via Specially Crafted Environment Variables"</a> at <a href="VMware" title="VMware">VMware</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities">Cyberwatch Vulnerabilities Database</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180822211959/https://www.cyberwatch.fr/en/vulnerabilities">Archived</a> 22 August 2018 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a>
<ul><li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-6271">CVE-2014-6271</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-6277">CVE-2014-6277</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-6278">CVE-2014-6278</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-7169">CVE-2014-7169</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-7186">CVE-2014-7186</a></li>
<li><a rel="nofollow" class="external text" href="https://www.cyberwatch.fr/en/vulnerabilities/CVE-2014-7187">CVE-2014-7187</a></li></ul></li>
<li><a rel="nofollow" class="external text" href="https://www.yeahhub.com/shellshock-vulnerability-exploitation-metasploit-framework/">ShellShock Exploitation with Metasploit Framework</a></li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Hacking_in_the_2010s730" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div id="Hacking_in_the_2010s730" style="font-size:114%;margin:0 4em">Hacking in the 2010s</div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div><table style="width:100%; margin:1px; display:inline-table;"><tbody><tr>

<td style="text-align:center; vertical-align:middle; padding:0 1px;" class=""><a href="Timeline_of_computer_security_hacker_history" class="mw-redirect" title="Timeline of computer security hacker history">Timeline</a></td>

</tr></tbody></table></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Major incidents</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2010</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Operation_Aurora" title="Operation Aurora">Operation Aurora</a> (publication of 2009 events)</li>
<li><a href="February_2010_Australian_cyberattacks" title="February 2010 Australian cyberattacks">Australian cyberattacks</a></li>
<li><a href="Operation_Olympic_Games" title="Operation Olympic Games">Operation Olympic Games</a></li>
<li><a href="Shadow_Network" title="Shadow Network">Operation ShadowNet</a></li>
<li><a href="Operation_Payback" title="Operation Payback">Operation Payback</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2011</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2011_Canadian_government_hackings" title="2011 Canadian government hackings">Canadian government</a></li>
<li><a href="DigiNotar" title="DigiNotar">DigiNotar</a></li>
<li><a href="DNSChanger" title="DNSChanger">DNSChanger</a></li>
<li><a href="HBGary" title="HBGary">HBGary Federal</a></li>
<li><a href="Operation_AntiSec" title="Operation AntiSec">Operation AntiSec</a></li>
<li><a href="2011_PlayStation_Network_outage" title="2011 PlayStation Network outage">PlayStation network outage</a></li>
<li><a href="RSA_SecurID#March_2011_system_compromise" title="RSA SecurID">RSA SecurID compromise</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2012</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2012_LinkedIn_hack" title="2012 LinkedIn hack">LinkedIn hack</a></li>
<li><a href="Stratfor_email_leak" title="Stratfor email leak">Stratfor email leak</a></li>
<li><a href="Operation_High_Roller" title="Operation High Roller">Operation High Roller</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2013</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2013_South_Korea_cyberattack" title="2013 South Korea cyberattack">South Korea cyberattack</a></li>
<li><a href="Snapchat#December_2013_hack" title="Snapchat">Snapchat hack</a></li>
<li><a href="June_25_cyber_terror" class="mw-redirect" title="June 25 cyber terror">Cyberterrorism attack of June 25</a></li>
<li><a href="Yahoo_data_breaches#August_2013:_breach" title="Yahoo data breaches">2013 Yahoo! data breach</a></li>
<li><a href="2013_Singapore_cyberattacks" title="2013 Singapore cyberattacks">Singapore cyberattacks</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2014</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anthem_medical_data_breach" title="Anthem medical data breach">Anthem medical data breach</a></li>
<li><a href="Operation_Tovar" title="Operation Tovar">Operation Tovar</a></li>
<li><a href="2014_celebrity_nude_photo_leak" title="2014 celebrity nude photo leak">2014 celebrity nude photo leak</a></li>
<li><a href="2014_JPMorgan_Chase_data_breach" title="2014 JPMorgan Chase data breach">2014 JPMorgan Chase data breach</a></li>
<li><a href="2014_Sony_Pictures_hack" title="2014 Sony Pictures hack">2014 Sony Pictures hack</a></li>
<li><a href="2014_Russian_hacker_password_theft" title="2014 Russian hacker password theft">Russian hacker password theft</a></li>
<li><a href="Yahoo_data_breaches#Late_2014:_breach" title="Yahoo data breaches">2014 Yahoo! data breach</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2015</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Office_of_Personnel_Management_data_breach" title="Office of Personnel Management data breach">Office of Personnel Management data breach</a></li>
<li><a href="HackingTeam#2015_data_breach" title="HackingTeam">HackingTeam</a></li>
<li><a href="Ashley_Madison_data_breach" title="Ashley Madison data breach">Ashley Madison data breach</a></li>
<li><a href="VTech#2015_data_breach" title="VTech">VTech data breach</a></li>
<li><a href="2015_Ukraine_power_grid_hack" title="2015 Ukraine power grid hack">Ukrainian Power Grid Cyberattack</a></li>
<li><a href="2015%E2%80%932016_SWIFT_banking_hack" title="2015–2016 SWIFT banking hack">SWIFT banking hack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2016</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Bangladesh_Bank_robbery" title="Bangladesh Bank robbery">Bangladesh Bank robbery</a></li>
<li><a href="Hollywood_Presbyterian_Medical_Center#Ransomware" title="Hollywood Presbyterian Medical Center">Hollywood Presbyterian Medical Center ransomware incident</a></li>
<li><a href="Commission_on_Elections_data_breach" title="Commission on Elections data breach">Commission on Elections data breach</a></li>
<li><a href="Democratic_National_Committee_cyber_attacks" title="Democratic National Committee cyber attacks">Democratic National Committee cyber attacks</a></li>
<li><a href="Vietnamese_airports_hackings" title="Vietnamese airports hackings">Vietnam Airport Hacks</a></li>
<li><a href="Democratic_Congressional_Campaign_Committee_cyber_attacks" title="Democratic Congressional Campaign Committee cyber attacks">DCCC cyber attacks</a></li>
<li><a href="2016_Indian_bank_data_breach" title="2016 Indian bank data breach">Indian Bank data breaches</a></li>
<li><a href="Surkov_leaks" title="Surkov leaks">Surkov leaks</a></li>
<li><a href="DDoS_attacks_on_Dyn" title="DDoS attacks on Dyn">Dyn cyberattack</a></li>
<li><a href="Russian_interference_in_the_2016_United_States_elections" title="Russian interference in the 2016 United States elections">Russian interference in the 2016 U.S. elections</a></li>
<li><a href="2016_Bitfinex_hack" title="2016 Bitfinex hack">2016 Bitfinex hack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2017</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="SHA-1#SHAttered_–_first_public_collision" title="SHA-1">SHAttered</a></li>
<li><a href="2017_Macron_e-mail_leaks" title="2017 Macron e-mail leaks">2017 Macron e-mail leaks</a></li>
<li><a href="WannaCry_ransomware_attack" title="WannaCry ransomware attack">WannaCry ransomware attack</a></li>
<li><a href="2017_Westminster_data_breach" title="2017 Westminster data breach">Westminster data breach</a></li>
<li><a href="Petya_(malware_family)" title="Petya (malware family)">Petya and NotPetya</a>
<ul><li><a href="2017_Ukraine_ransomware_attacks" title="2017 Ukraine ransomware attacks">2017 Ukraine ransomware attacks</a></li></ul></li>
<li><a href="2017_Equifax_data_breach" title="2017 Equifax data breach">Equifax data breach</a></li>
<li><a href="Deloitte#E-mail_hack" title="Deloitte">Deloitte breach</a></li>
<li><a href="Disqus#October_2017_security_breach" title="Disqus">Disqus breach</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2018</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Trustico#DigiCert_and_Trustico_spat,_2018" title="Trustico">Trustico</a></li>
<li><a href="Atlanta_government_ransomware_attack" title="Atlanta government ransomware attack">Atlanta cyberattack</a></li>
<li><a href="2018_SingHealth_data_breach" title="2018 SingHealth data breach">SingHealth data breach</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2019</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="2019_cyberattacks_on_Sri_Lanka" title="2019 cyberattacks on Sri Lanka">Sri Lanka cyberattack</a></li>
<li><a href="2019_Baltimore_ransomware_attack" title="2019 Baltimore ransomware attack">Baltimore ransomware attack</a></li>
<li><a href="2019_Bulgarian_Revenue_Agency_hack" title="2019 Bulgarian Revenue Agency hack">Bulgarian revenue agency hack</a></li>
<li><a href="WhatsApp_snooping_scandal" title="WhatsApp snooping scandal">WhatsApp snooping scandal</a></li>
<li><a href="Jeff_Bezos_phone_hacking_incident" title="Jeff Bezos phone hacking incident">Jeff Bezos phone hacking incident</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Hacktivism" title="Hacktivism">Hacktivism</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Anonymous_(hacker_group)" title="Anonymous (hacker group)">Anonymous</a>
<ul><li><a href="Timeline_of_events_associated_with_Anonymous" title="Timeline of events associated with Anonymous">associated events</a></li></ul></li>
<li><a href="CyberBerkut" title="CyberBerkut">CyberBerkut</a></li>
<li><a href="Gay_Nigger_Association_of_America" title="Gay Nigger Association of America">GNAA</a></li>
<li><a href="Goatse_Security" title="Goatse Security">Goatse Security</a></li>
<li><a href="Lizard_Squad" title="Lizard Squad">Lizard Squad</a></li>
<li><a href="LulzRaft" title="LulzRaft">LulzRaft</a></li>
<li><a href="LulzSec" title="LulzSec">LulzSec</a></li>
<li><a href="DDoS_attacks_on_Dyn#Perpetrators" title="DDoS attacks on Dyn">New World Hackers</a></li>
<li><a href="NullCrew" title="NullCrew">NullCrew</a></li>
<li><a href="OurMine" title="OurMine">OurMine</a></li>
<li><a href="PayPal_14" title="PayPal 14">PayPal 14</a></li>
<li><a href="RedHack" title="RedHack">RedHack</a></li>
<li><a href="Teamp0ison" title="Teamp0ison">Teamp0ison</a></li>
<li><a href="The_Dark_Overlord_(hacker_group)" title="The Dark Overlord (hacker group)">TDO</a></li>
<li><a href="UGNazi" title="UGNazi">UGNazi</a></li>
<li><a href="Ukrainian_Cyber_Alliance" title="Ukrainian Cyber Alliance">Ukrainian Cyber Alliance</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Groups</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Appin_(company)" title="Appin (company)">Appin</a></li>
<li><a href="Bangladesh_Black_Hat_Hackers" title="Bangladesh Black Hat Hackers">Bangladesh Black Hat Hackers</a></li>
<li><a href="Bureau_121" title="Bureau 121">Bureau 121</a></li>
<li><a href="Charming_Kitten" title="Charming Kitten">Charming Kitten</a></li>
<li><a href="Cozy_Bear" title="Cozy Bear">Cozy Bear</a></li>
<li><a href="Dark_Basin" title="Dark Basin">Dark Basin</a></li>
<li><a href="DarkMatter_Group" title="DarkMatter Group">DarkMatter</a></li>
<li><a href="Elfin_Team" title="Elfin Team">Elfin Team</a></li>
<li><a href="Equation_Group" title="Equation Group">Equation Group</a></li>
<li><a href="Fancy_Bear" title="Fancy Bear">Fancy Bear</a></li>
<li><a href="Stuxnet#History" title="Stuxnet">GOSSIPGIRL</a> (confederation)</li>
<li><a href="Guccifer_2.0" title="Guccifer 2.0">Guccifer 2.0</a></li>
<li><a href="HackingTeam" title="HackingTeam">Hacking Team</a></li>
<li><a href="Helix_Kitten" title="Helix Kitten">Helix Kitten</a></li>
<li><a href="Iranian_Cyber_Army" title="Iranian Cyber Army">Iranian Cyber Army</a></li>
<li><a href="Islamic_State_Hacking_Division" title="Islamic State Hacking Division">Islamic State Hacking Division</a></li>
<li><a href="Lazarus_Group" title="Lazarus Group">Lazarus Group</a>
<ul><li><a href="Lazarus_Group#BlueNorOff" title="Lazarus Group">BlueNorOff</a></li>
<li><a href="Lazarus_Group#AndAriel" title="Lazarus Group">AndAriel</a></li></ul></li>
<li><a href="Lords_of_Dharmaraja" title="Lords of Dharmaraja">Lords of Dharmaraja</a></li>
<li><a href="NSO_Group" title="NSO Group">NSO Group</a></li>
<li><a href="Numbered_Panda" title="Numbered Panda">Numbered Panda</a></li>
<li><a href="PLA_Unit_61398" title="PLA Unit 61398">PLA Unit 61398</a></li>
<li><a href="PLA_Unit_61486" title="PLA Unit 61486">PLA Unit 61486</a></li>
<li><a href="PLATINUM_(cybercrime_group)" title="PLATINUM (cybercrime group)">PLATINUM</a></li>
<li><a href="Pranknet" title="Pranknet">Pranknet</a></li>
<li><a href="Red_Apollo" title="Red Apollo">Red Apollo</a></li>
<li><a href="Rocket_Kitten" title="Rocket Kitten">Rocket Kitten</a></li>
<li><a href="Stealth_Falcon" title="Stealth Falcon">Stealth Falcon</a></li>
<li><a href="Syrian_Electronic_Army" title="Syrian Electronic Army">Syrian Electronic Army</a></li>
<li><a href="Tailored_Access_Operations" title="Tailored Access Operations">Tailored Access Operations</a></li>
<li><a href="The_Shadow_Brokers" title="The Shadow Brokers">The Shadow Brokers</a></li>
<li><a href="XDedic" title="XDedic">xDedic</a></li>
<li><a href="Yemen_Cyber_Army" title="Yemen Cyber Army">Yemen Cyber Army</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Hacker" title="Hacker">Individuals</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Ryan_Ackroyd" title="Ryan Ackroyd">Ryan Ackroyd</a></li>
<li><a href="Mustafa_Al-Bassam" title="Mustafa Al-Bassam">Mustafa Al-Bassam</a></li>
<li><a href="Kim_Anh_Vo" title="Kim Anh Vo">Kim Anh Vo</a></li>
<li><a href="George_Hotz" title="George Hotz">George Hotz</a></li>
<li><a href="Guccifer" title="Guccifer">Guccifer</a></li>
<li><a href="Elliott_Gunton" title="Elliott Gunton">Elliott Gunton</a></li>
<li><a href="Jeremy_Hammond" title="Jeremy Hammond">Jeremy Hammond</a></li>
<li><a href="Sam_Hocevar" title="Sam Hocevar">Sam Hocevar</a></li>
<li><a href="Junaid_Hussain" title="Junaid Hussain">Junaid Hussain</a></li>
<li><a href="MLT_(hacktivist)" title="MLT (hacktivist)">MLT</a></li>
<li><a href="Hector_Monsegur" title="Hector Monsegur">Sabu</a></li>
<li><a href="Roman_Seleznev" title="Roman Seleznev">Track2</a></li>
<li><a href="Topiary_(hacktivist)" title="Topiary (hacktivist)">Topiary</a></li>
<li><a href="The_Jester_(hacktivist)" title="The Jester (hacktivist)">The Jester</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Major <a href="Vulnerability_(computer_security)" title="Vulnerability (computer security)">vulnerabilities</a><br>publicly <a href="Full_disclosure_(computer_security)" title="Full disclosure (computer security)">disclosed</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Evercookie" title="Evercookie">Evercookie</a> (2010)</li>
<li><a href="ISeeYou" title="ISeeYou">iSeeYou</a> (2013)</li>
<li><a href="Heartbleed" title="Heartbleed"> Heartbleed</a> (2014)</li>
<li> (2014)</li>
<li><a href="POODLE" title="POODLE">POODLE</a> (2014)</li>
<li><a href="Rootpipe" title="Rootpipe">Rootpipe</a> (2014)</li>
<li><a href="Row_hammer" title="Row hammer">Row hammer</a> (2014)</li>
<li><a href="Signalling_System_No._7#Protocol_security_vulnerabilities" title="Signalling System No. 7">SS7 vulnerabilities</a> (2014)</li>
<li><a href="WinShock" title="WinShock">WinShock</a> (2014)</li>
<li><a href="JASBUG" title="JASBUG">JASBUG</a> (2015)</li>
<li><a href="Stagefright_(bug)" title="Stagefright (bug)">Stagefright</a> (2015)</li>
<li><a href="DROWN_attack" title="DROWN attack">DROWN</a> (2016)</li>
<li><a href="Badlock" title="Badlock">Badlock</a> (2016)</li>
<li><a href="Dirty_COW" title="Dirty COW">Dirty COW</a> (2016)</li>
<li><a href="Cloudbleed" title="Cloudbleed">Cloudbleed</a> (2017)</li>
<li><a href="Broadcom_Corporation#soc-wifi-vulns" title="Broadcom Corporation">Broadcom Wi-Fi</a> (2017)</li>
<li><a href="EternalBlue" title="EternalBlue">EternalBlue</a> (2017)</li>
<li><a href="DoublePulsar" title="DoublePulsar">DoublePulsar</a> (2017)</li>
<li><a href="Intel_Active_Management_Technology#Silent_Bob_is_Silent" title="Intel Active Management Technology">Silent Bob is Silent</a> (2017)</li>
<li><a href="KRACK" title="KRACK">KRACK</a> (2017)</li>
<li><a href="ROCA_vulnerability" title="ROCA vulnerability">ROCA vulnerability</a> (2017)</li>
<li><a href="BlueBorne_(security_vulnerability)" title="BlueBorne (security vulnerability)">BlueBorne</a> (2017)</li>
<li><a href="Meltdown_(security_vulnerability)" title="Meltdown (security vulnerability)">Meltdown</a> (2018)</li>
<li><a href="Spectre_(security_vulnerability)" title="Spectre (security vulnerability)">Spectre</a> (2018)</li>
<li><a href="EFAIL" title="EFAIL">EFAIL</a> (2018)</li>
<li><a href="Exactis" title="Exactis">Exactis</a> (2018)</li>
<li><a href="Speculative_Store_Bypass" title="Speculative Store Bypass">Speculative Store Bypass</a> (2018)</li>
<li><a href="Lazy_FP_state_restore" title="Lazy FP state restore">Lazy FP state restore</a> (2018)</li>
<li><a href="TLBleed" title="TLBleed">TLBleed</a> (2018)</li>
<li><a href="SigSpoof" title="SigSpoof">SigSpoof</a> (2018)</li>
<li><a href="Foreshadow" title="Foreshadow">Foreshadow</a> (2018)</li>
<li><a href="Wi-Fi_Protected_Access#Dragonblood_attack" title="Wi-Fi Protected Access">Dragonblood</a> (2019)</li>
<li><a href="Microarchitectural_Data_Sampling" title="Microarchitectural Data Sampling">Microarchitectural Data Sampling</a> (2019)</li>
<li><a href="BlueKeep" title="BlueKeep">BlueKeep</a> (2019)</li>
<li><a href="Kr00k" title="Kr00k">Kr00k</a> (2019)</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Malware" title="Malware">Malware</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">2010</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Ransomware#Bad_Rabbit" title="Ransomware">Bad Rabbit</a></li>
<li><a href="BlackEnergy#BlackEnergy_2_(BE2)" title="BlackEnergy"> Black Energy 2</a></li>
<li><a href="SpyEye" title="SpyEye">SpyEye</a></li>
<li><a href="Stuxnet" title="Stuxnet">Stuxnet</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2011</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Coreflood" title="Coreflood">Coreflood</a></li>
<li><a href="Alureon" title="Alureon">Alureon</a></li>
<li><a href="Duqu" title="Duqu">Duqu</a></li>
<li><a href="Kelihos_botnet" title="Kelihos botnet">Kelihos</a></li>
<li><a href="Metulji_botnet" title="Metulji botnet">Metulji botnet</a></li>
<li><a href="Stars_virus" title="Stars virus">Stars</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2012</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Carna_botnet" title="Carna botnet">Carna</a></li>
<li><a href="Dexter_(malware)" title="Dexter (malware)">Dexter</a></li>
<li><a href="FBI_MoneyPak_Ransomware" title="FBI MoneyPak Ransomware">FBI</a></li>
<li><a href="Flame_(malware)" title="Flame (malware)">Flame</a></li>
<li><a href="Mahdi_(malware)" title="Mahdi (malware)">Mahdi</a></li>
<li><a href="Red_October_(malware)" title="Red October (malware)">Red October</a></li>
<li><a href="Shamoon" title="Shamoon">Shamoon</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2013</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CryptoLocker" title="CryptoLocker">CryptoLocker</a></li>
<li><a href="2013_South_Korea_cyberattack" title="2013 South Korea cyberattack">DarkSeoul</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2014</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Brambul" title="Brambul">Brambul</a></li>
<li><a href="BlackEnergy#BlackEnergy_3_(BE3)" title="BlackEnergy"> Black Energy 3</a></li>
<li><a href="Carbanak" title="Carbanak">Carbanak</a></li>
<li><a href="Careto_(malware)" title="Careto (malware)">Careto</a></li>
<li><a href="DarkHotel" title="DarkHotel">DarkHotel</a></li>
<li><a href="Duqu_2.0" title="Duqu 2.0">Duqu 2.0</a></li>
<li><a href="FinFisher" title="FinFisher">FinFisher</a></li>
<li><a href="Gameover_ZeuS" title="Gameover ZeuS">Gameover ZeuS</a></li>
<li><a href="Regin_(malware)" title="Regin (malware)">Regin</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2015</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Dridex" title="Dridex">Dridex</a></li>
<li><a href="Hidden_Tear" title="Hidden Tear">Hidden Tear</a></li>
<li><a href="Rombertik" title="Rombertik">Rombertik</a></li>
<li><a href="TeslaCrypt" title="TeslaCrypt">TeslaCrypt</a></li>
<li><a href="Project_Sauron" title="Project Sauron">Project Sauron</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2016</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Hitler-Ransomware" title="Hitler-Ransomware">Hitler</a></li>
<li><a href="Jigsaw_(ransomware)" title="Jigsaw (ransomware)">Jigsaw</a></li>
<li><a href="KeRanger" title="KeRanger">KeRanger</a></li>
<li><a href="Necurs_botnet" title="Necurs botnet">Necurs</a></li>
<li><a href="MEMZ" title="MEMZ">MEMZ</a></li>
<li><a href="Mirai_(malware)" title="Mirai (malware)">Mirai</a></li>
<li><a href="Pegasus_(spyware)" title="Pegasus (spyware)">Pegasus</a></li>
<li><a href="Petya_(malware_family)" title="Petya (malware family)">Petya and NotPetya</a></li>
<li><a href="X-Agent" title="X-Agent">X-Agent</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2017</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="BrickerBot" title="BrickerBot">BrickerBot</a></li>
<li><a href="Kirk_Ransomware" title="Kirk Ransomware">Kirk</a></li>
<li><a href="LogicLocker" title="LogicLocker">LogicLocker</a></li>
<li><a href="Rensenware" title="Rensenware">Rensenware</a></li>
<li><a href="Triton_(malware)" title="Triton (malware)">Triton</a></li>
<li><a href="WannaCry_ransomware_attack" title="WannaCry ransomware attack">WannaCry</a></li>
<li><a href="Xafecopy_Trojan" title="Xafecopy Trojan">XafeCopy</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2018</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="VPNFilter" title="VPNFilter">VPNFilter</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">2019</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Grum_botnet" title="Grum botnet">Grum</a></li>
<li><a href="Joanap" title="Joanap">Joanap</a></li>
<li><a href="NetTraveler" title="NetTraveler">NetTraveler</a></li>
<li><a href="Chaos_Computer_Club#Staatstrojaner_affair" title="Chaos Computer Club">R2D2</a></li>
<li><a href="Tiny_Banker_Trojan" title="Tiny Banker Trojan">Tinba</a></li>
<li><a href="Titanium_(malware)" title="Titanium (malware)">Titanium</a></li>
<li><a href="ZeroAccess_botnet" title="ZeroAccess botnet">ZeroAccess botnet</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2024-08-15" href="https://en.wikipedia.org/wiki/?title=Shellshock_(software_bug)&amp;oldid=1240395044">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>