Oracle Security Alert for CVE-2014-7169
Security Alert CVE-2014-7169 addresses a publicly disclosed vulnerability affecting GNU Bash. GNU Bash is a popular open source command line shell incorporated into Linux and other widely used operating systems. This vulnerability affects multiple Oracle products. This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password. A remote user can exploit this vulnerability to execute arbitrary code on systems that are running affected versions of Bash.
Oracle is still investigating this issue and will provide fixes for affected
products as soon as they have been fully tested and determined to provide
effective mitigation against the vulnerability.
The fixes that are available for immediate application by customers
are listed in the Patch Availability Table. This Security
Alert will be updated when fixes are available for additional affected Oracle
products without sending additional emails to customers. Customers should check
this page for updates.
Due to the severity, public disclosure, and reports of active
exploitation of CVE-2014-7169, Oracle strongly recommends that customers apply
the fixes provided by this Security Alert as soon as they are released by
Oracle.