{"id":10850,"date":"2014-09-25T18:24:23","date_gmt":"2014-09-25T09:24:23","guid":{"rendered":"http:\/\/vitalify.jp\/blog\/?p=10850"},"modified":"2014-09-25T18:25:34","modified_gmt":"2014-09-25T09:25:34","slug":"bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6","status":"publish","type":"post","link":"https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html","title":{"rendered":"bash\u306e\u8106\u5f31\u6027(CVE-2014-6271) \u5bfe\u5fdc\u306b\u3064\u3044\u3066"},"content":{"rendered":"<p>\u3069\u3046\u3082\u3002\u4f0a\u85e4\u3067\u3059\u3002<\/p>\n<p>\u6700\u8fd1\u5168\u304f\u66f4\u65b0\u3067\u304d\u3066\u304a\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001\u4e45\u3057\u3076\u308a\u306b\u66f4\u65b0\u3057\u307e\u3059\u3002<br \/>\nbash\u306b\u8106\u5f31\u6027\u304c\u78ba\u8a8d\u3055\u308c\u305f\u3068\u3044\u3046\u60c5\u5831\u304c\u5165\u3063\u3066\u304d\u305f\u306e\u3067\u30c1\u30a7\u30c3\u30af\u65b9\u6cd5\u3068\u5bfe\u7b56\u65b9\u6cd5\u3092\u5171\u6709\u3057\u307e\u3059\u3002<\/p>\n<p>\u25a0\u30c1\u30a7\u30c3\u30af\u65b9\u6cd5<br \/>\n\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u300cvulnerable\u300d\u304c\u8868\u793a\u3055\u308c\u305f\u5834\u5408\u3001CVE-2014-6271\u306e\u5f71\u97ff\u3092\u53d7\u3051\u308b\u53ef\u80fd\u6027\u3042\u308a\u3002<br \/>\n$ env x='() { :;}; echo vulnerable&#8217; bash -c &#8220;echo bash&#8221;<br \/>\nvulnerable<br \/>\nbash<\/p>\n<p>\u25a0\u73fe\u5728\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u78ba\u8a8d<br \/>\n$ rpm -qa bash<br \/>\nbash-4.1.2-9.el6_2.x86_64<\/p>\n<p><!--more--><\/p>\n<p>\u25a0\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u66f4\u65b0<br \/>\n$ yum -y update bash<br \/>\nLoaded plugins: fastestmirror, priorities, security<br \/>\nLoading mirror speeds from cached hostfile<br \/>\n * base: ftp.iij.ad.jp<br \/>\n * extras: ftp.iij.ad.jp<br \/>\n * rpmforge: ftp.kddilabs.jp<br \/>\n * updates: ftp.tsukuba.wide.ad.jp<br \/>\n\u30fb<br \/>\n\u30fb<br \/>\n\u30fb<br \/>\n\u30fb<br \/>\nTransaction Test Succeeded<br \/>\nRunning Transaction<br \/>\n  Updating   : bash-4.1.2-15.el6_5.1.x86_64      1\/2<br \/>\n  Cleanup    : bash-4.1.2-9.el6_2.x86_64         2\/2<br \/>\n  Verifying  : bash-4.1.2-15.el6_5.1.x86_64      1\/2<br \/>\n  Verifying  : bash-4.1.2-9.el6_2.x86_64         2\/2<\/p>\n<p>Updated:<br \/>\n  bash.x86_64 0:4.1.2-15.el6_5.1<\/p>\n<p>\u25a0\u518d\u30c1\u30a7\u30c3\u30af\u65b9\u6cd5<br \/>\n$ env x='() { :;}; echo vulnerable&#8217; bash -c &#8220;echo bash&#8221;<br \/>\nbash: warning: x: ignoring function definition attempt<br \/>\nbash: error importing function definition for `x&#8217;<br \/>\nbash<\/p>\n<p>\u25a0\u66f4\u65b0\u5f8c\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u78ba\u8a8d<br \/>\n# rpm -qa bash<br \/>\nbash-4.1.2-15.el6_5.1.x86_64<\/p>\n<p>\u3053\u308c\u3067\u4e00\u5148\u305a\u5b89\u5fc3\u3067\u3059\u3002<\/p>\n<p>\u3067\u306f\u3067\u306f\u3002<\/p>\n<div class='wp_social_bookmarking_light'>\n            <div class=\"wsbl_facebook_like\"><div id=\"fb-root\"><\/div><fb:like href=\"https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html\" layout=\"button_count\" action=\"like\" share=\"false\" show_faces=\"false\" ><\/fb:like><\/div>\n            <div class=\"wsbl_google_plus_one\"><g:plusone size=\"medium\" annotation=\"none\" href=\"https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html\" ><\/g:plusone><\/div>\n            <div class=\"wsbl_hatena_button\"><a href=\"\/\/b.hatena.ne.jp\/entry\/https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html\" class=\"hatena-bookmark-button\" data-hatena-bookmark-title=\"bash\u306e\u8106\u5f31\u6027(CVE-2014-6271) \u5bfe\u5fdc\u306b\u3064\u3044\u3066\" data-hatena-bookmark-layout=\"standard\" title=\"\u3053\u306e\u30a8\u30f3\u30c8\u30ea\u30fc\u3092\u306f\u3066\u306a\u30d6\u30c3\u30af\u30de\u30fc\u30af\u306b\u8ffd\u52a0\"> <img src=\"\/\/b.hatena.ne.jp\/images\/entry-button\/button-only@2x.png\" alt=\"\u3053\u306e\u30a8\u30f3\u30c8\u30ea\u30fc\u3092\u306f\u3066\u306a\u30d6\u30c3\u30af\u30de\u30fc\u30af\u306b\u8ffd\u52a0\" width=\"20\" height=\"20\" style=\"border: none;\" \/><\/a><script type=\"text\/javascript\" src=\"\/\/b.hatena.ne.jp\/js\/bookmark_button.js\" charset=\"utf-8\" async=\"async\"><\/script><\/div>\n            <div class=\"wsbl_tumblr\"><a href=\"\/\/www.tumblr.com\/share?v=3&u=https%3A%2F%2Fvitalify.jp%2Fblog%2F2014%2F09%2Fbash%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7cve-2014-6271-%25e5%25af%25be%25e5%25bf%259c%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6.html&t=bash%E3%81%AE%E8%84%86%E5%BC%B1%E6%80%A7%28CVE-2014-6271%29%20%E5%AF%BE%E5%BF%9C%E3%81%AB%E3%81%A4%E3%81%84%E3%81%A6\" title=\"Share on Tumblr\" style=\"display:inline-block; text-indent:-9999px; overflow:hidden; width:81px; height:20px; background:url('\/\/platform.tumblr.com\/v1\/share_1.png') top left no-repeat transparent;\">Share on Tumblr<\/a><\/div>\n            <div class=\"wsbl_twitter\"><a href=\"https:\/\/twitter.com\/share\" class=\"twitter-share-button\" data-url=\"https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html\" data-text=\"bash\u306e\u8106\u5f31\u6027(CVE-2014-6271) \u5bfe\u5fdc\u306b\u3064\u3044\u3066\" data-lang=\"ja\">Tweet<\/a><\/div>\n    <\/div>\n<br class='wp_social_bookmarking_light_clear' \/>\n","protected":false},"excerpt":{"rendered":"<p>\u3069\u3046\u3082\u3002\u4f0a\u85e4\u3067\u3059\u3002 \u6700\u8fd1\u5168\u304f\u66f4\u65b0\u3067\u304d\u3066\u304a\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u304c\u3001\u4e45\u3057\u3076\u308a\u306b\u66f4\u65b0\u3057\u307e\u3059\u3002 bash\u306b\u8106\u5f31\u6027\u304c\u78ba\u8a8d\u3055\u308c\u305f\u3068\u3044\u3046\u60c5\u5831\u304c\u5165\u3063\u3066\u304d\u305f\u306e\u3067\u30c1\u30a7\u30c3\u30af\u65b9\u6cd5\u3068\u5bfe\u7b56\u65b9\u6cd5\u3092\u5171\u6709\u3057\u307e\u3059\u3002 \u25a0\u30c1\u30a7\u30c3\u30af\u65b9\u6cd5 \u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u300cvu &hellip; <a href=\"https:\/\/vitalify.jp\/blog\/2014\/09\/bash%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7cve-2014-6271-%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6.html\" class=\"more-link more_btn\"><span class=\"screen-reader-text\">&#8220;bash\u306e\u8106\u5f31\u6027(CVE-2014-6271) \u5bfe\u5fdc\u306b\u3064\u3044\u3066&#8221; \u306e<\/span>\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[44],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/posts\/10850"}],"collection":[{"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/comments?post=10850"}],"version-history":[{"count":3,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/posts\/10850\/revisions"}],"predecessor-version":[{"id":10853,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/posts\/10850\/revisions\/10853"}],"wp:attachment":[{"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/media?parent=10850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/categories?post=10850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vitalify.jp\/blog\/wp-json\/wp\/v2\/tags?post=10850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}