在 Dell Data Protection Virtual Edition 中发布“Shell 冲击漏洞”
Résumé: 本文提供有关 Shell shock Bash Bug CVE-2014-6271 安全漏洞及其如何影响 Dell Data Protection |Virtual Edition 软件。
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Symptômes
受影响的产品:
- Dell Data Protection | Virtual Edition
受影响的版本:
- v9.2 及更低版本
通过从 bash shell 提示符处运行以下命令来测试此漏洞:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
如果在输出中显示单词 vulnerable ,则计算机容易受到该漏洞的攻击。
即使存在漏洞,攻击者也必须能够访问 VE 服务器上的特定端口才能利用该漏洞。
最佳实践是 Dell Data Protection |Virtual Edition 服务器不面向互联网,而是使用代理服务来满足面向互联网的要求。
如果 Dell Data Protection |Virtual Edition 不面向互联网,因此无法在组织外部利用 ShellShock 问题。
Cause
较旧版本的 Dell Data Protection |Virtual Edition 容易受到 Ubuntu 安全通知 USN-2362-1 中所述的 bash shell 中的漏洞影响,通常称为 Shell 撞击漏洞。
问题参数:
- Dell Data Protection |Virtual Edition 控制台和 SSH 服务器使用 bash shell,可利用该 shell 将尾随代码传递到 bash shell 并获得对命令环境的未经授权的访问权限。
- Dell Data Protection |加密预启动身份验证 (PBA) 软件,例如自加密驱动器 (SED) 管理或用于验证客户端的硬件加密加速器 (HCA)。
Résolution
此问题已在 Dell Data Protection |Virtual Edition v9.3 及更高版本。
要纠正此问题:
- 打开 Virtual Edition 远程桌面控制台。
- 从主菜单中选择 Launch Shell选项,然后执行以下步骤:
- 键入命令:
su ddpsupport - 按<Enter>键。
- 出现提示时,输入为
ddpsupport用户身份登录。 - 有一个更新提示,开头为
ddpsupport@。 - 键入命令:
sudo apt-get update- 此命令使用互联网联系 Ubuntu 更新服务器,并请求所需的相关更新。
- 键入命令:
sudo apt-get install bash
更新完成后,通过再次测试确认更新解决了漏洞。
注意: 命令的输出中没有“ 易受攻击” 一词:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
Informations supplémentaires
更多参考资料
CVE-2014-6271 在 NIST 网站上
Produits concernés
Dell EncryptionPropriétés de l’article
Numéro d’article: 000129498
Type d’article: Solution
Dernière modification: 26 août 2026
Version: 10
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.