Shellshock bug: New security vulnerability is bigger than Heartbleed

Experts have discovered a new security vulnerability – dubbed Shellshock bug or Bash – affecting hundreds of millions of computers, servers and devices.

The flaw has been found in a software component known as Bash, which is a part of many Linux systems as well as Apple’s Mac operating system.

Shellshock bug can be used to remotely take control of almost any system using Bash, researchers said.

Some experts said Shellshock bug was more serious than Heartbleed, discovered in April.

Some 500,000 machines worldwide were thought to have been vulnerable to Heartbleed. But early estimates, which experts said were conservative, suggest that Shellshock could hit at least 500 million machines.

The problem is particularly serious given that many web servers are run using the Apache system, software which includes the Bash component.

Bash – which stands for Bourne-Again SHell – is a command prompt on many Unix computers. Unix is an operating system on which many others are built, such as Linux and Mac OS.

Shellshock bug has been found in a software component known as Bash, which is a part of many Linux systems as well as Apple’s Mac operating system

The US Computer Emergency Readiness Team (US-CERT) issued a warning about the bug, urging system administrators to apply patches.

However, other security researchers warned that the patches were “incomplete” and would not fully secure systems.

Of particular concern to security experts is the simplicity of carrying out attacks that make use of the bug.

Cybersecurity specialists Rapid7 rated the Bash bug as 10 out of 10 for severity, but “low” on complexity – a relatively easy vulnerability for hackers to capitalize on.

Security companies have suggested that there is evidence Shellshock is being used by hackers.

The new bug has turned the spotlight, once again, onto the reliance the technology industry has on products built and maintained by small teams often made up of volunteers.

Heartbleed was a bug related to open source cryptographic software OpenSSL. After the bug became public, major tech firms moved to donate large sums of money to the team responsible for maintaining the software.

Similarly, the responsibility for Bash lies with just one person – Chet Ramey, a developer based at Case Western Reserve University in Ohio.

aKShnpOXqn0
Nancy Clayson

Nancy is a young, full of life lady who joined the team shortly after the BelleNews site started to run. She is focused on bringing up to light all the latest news from the technology industry. In her opinion the hi-tech expresses the humanity intellectual level. Nancy is an active person; she enjoys sports and delights herself in doing gardening in her spare time, as well as reading, always searching for new topics for her articles.

Recent Posts

UCLA Protests: Police Clash with Protesters as Officers Clear Pro-Palestinian Encampment

President Joe Biden has urged pro-Palestinian protesters on university campuses to uphold the rule of…

2 days ago

Mufasa: Blue Ivy Carter Joins Voice Cast of The Lion King Prequel

Blue Ivy Carter has joined the voice cast of The Lion King prequel Mufasa: The…

2 days ago

Deadly Tornadoes Hit Oklahoma Leaving Thousands Without Power and Causing Serious Damage

At least five people, including a four-month-old baby, have been killed after dozens of tornadoes…

5 days ago

Harvey Weinstein in Hospital After Conviction Overturned

Harvey Weinstein has been hospitalized just days after his 2020 rape conviction in New York…

7 days ago

Hamas Releases Video of Two Hostages, Including a Kidnapped US Citizen

Hamas has published a video showing the first proof of life of US and Israeli…

7 days ago

Trump Trial: Prosecutors and Attorneys Deliver Opening Statements

Prosecutors and Donald Trump’s attorneys delivered opening statements and the first witness was called on…

2 weeks ago