在 Dell Data Protection Virtual Edition 中抨擊「Shell Shock 漏洞」
Résumé: 本文提供 Shell shock Bash 漏洞 CVE-2014-6271 安全性漏洞的相關資訊,以及此漏洞如何影響 Dell Data Protection |虛擬版軟體。
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Symptômes
受影響的產品:
- Dell Data Protection | Virtual Edition
受影響的版本:
- v9.2 和更舊版本
從 bash shell 提示字元執行下列命令,以測試此漏洞:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
如果輸出中出現 「易受攻擊 」一詞,則計算機容易受到攻擊。
即使存在漏洞,攻擊者也必須能夠訪問 VE 伺服器上的特定埠才能使用該漏洞。
Dell Data Protection |Virtual Edition 伺服器並非面向網際網路,而是使用代理服務來滿足因特網需求。
如果 Dell Data Protection |Virtual Edition 不面向 Internet,ShellShock 問題無法在組織外部利用。
Cause
舊版 Dell Data Protection |Virtual Edition 容易受到 Ubuntu 安全性通知 USN-2362-1 中所述的 bash shell 漏洞攻擊,通常稱為 Shell Shock 漏洞。
問題參數:
- 戴爾數據保護 |Virtual Edition 主控台和 SSH 伺服器使用 bash shell,可透過將尾隨的程式碼傳遞到 bash shell 並未經授權存取命令環境來利用此漏洞。
- Dell Data Protection |用於驗證用戶端的加密開機前驗證 (PBA) 軟體,例如自我加密磁碟機 (SED) 管理或硬體加密加速器 (HCA)。
Résolution
此問題已在 Dell Data Protection |Virtual Edition v9.3 及更新版本。
若要修正此問題:
- 開啟 Virtual Edition 遠端桌面主控台。
- 從主功能表中選擇 啟動 Shell 選項,然後按照下列步驟操作:
- 輸入命令:
su ddpsupport - 按下 Enter 鍵。
- 出現提示時,請輸入為
ddpsupport使用者。 - 更新提示的開頭為
ddpsupport@。 - 輸入命令:
sudo apt-get update- 此命令會使用網際網路聯絡 Ubuntu 更新伺服器,並要求所需的相關更新。
- 輸入命令:
sudo apt-get install bash
更新完成後,通過再次測試確認更新解決了漏洞。
注意: 命令輸出中不存在 「易受攻擊 」一詞:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
Informations supplémentaires
更多參考資料
CVE-2014-6271 在 NIST 網站上
Produits concernés
Dell EncryptionPropriétés de l’article
Numéro d’article: 000129498
Type d’article: Solution
Dernière modification: 26 août 2026
Version: 10
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.