ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Shellshock (aka Bashdoor) Bug and VMware – Where are We?

By Vladan SEGET | Last Updated: March 17, 2015

Shares

Recent Shellshock bug in Linux Bash revealed the 24th of September was often compared to Heartbleed bug in terms of severity. Just to remind you, it affects all Linux/Unix systems using the original bash (which has been re-released for new distros already).

OSX users were told to deactivate the advanced Unix services, but apparently even after the release of Apple's patches there are still some areas under flaw.

The exploit is apparently very simple to use that many non patched Linux servers were used as botnets to launch DDOS attacks. The US government-backed National Vulnerability Database rated Shellshock 10/10 for severity.

Wikipedia:

Attackers exploited Shellshock within hours of the initial disclosure by creating botnets on compromised computers to perform distributed denial-of-service attacks and vulnerability scanning. Millions of attacks and probes related to the bug were recorded by security companies in the days following the disclosure.

VMware's products were also affected. Not the ESXi hypervisors as they don't use the bash but busybox. Some older version of VMware hypervisors are however affected because they are (were) using bash (ESX 4.0 and ESX 4.1).

Most Virtual appliances using bash will needs to be patched or if you're deploying new environment you can simply re-download new, updated release.

Here is an example of VCSA 5.5 U2a which is up to date (Shellshock patched) release of vCenter Server Linux appliance available from MyVMware…

vCenter Server Appliance - ShellShock Bug

If you are running unpatched VCSA then simply go to the Update TAB (via https://IP_of_VCSA:5480 ) and hit the Check updates button and then the Install updates button. It's fast, convenient and easy.

VCSA patched

VMware is working to release patches (even for older, unsupported products like vSphere 4.0). There is a VMware KB that is updated on regular basis and which informs about patches and products concerned by the security flaw. KB 2090740:  Bash Code Injection Vulnerability via Specially Crafted Environment Variables (CVE-2014-6271 CVE-2014-7169, aka “Shellshock”).

Here are the product details as of today (but the list changes every day as VMware works on the problem and adding more links):

VMware (Virtual) Appliances

  • EVO:RAIL 1.x (EVO:Rail ships with vCenter Server Appliance and vCenter Log Insight and will be re-released with updated versions of these appliances)
  • Horizon DaaS Platform 6.x (See VMSA-2014-0010 for remediation details)
  • Horizon Workspace 1.x, 2.x. (See VMSA-2014-0010 for remediation details)
  • IT Business Management Suite 1.x (See VMSA-2014-0010 for remediation details)
  • NSX for Multi-Hypervisor 4.x (See VMSA-2014-0010 for remediation details)
  • NSX for vSphere 6.x (See VMSA-2014-0010 for remediation details)
  • NVP 3.x (See VMSA-2014-0010 for remediation details)
  • vCenter Converter Standalone 5.x (vCenter Converter Standalone is not a Virtual Appliance but includes a vulnerable version of bash)
  • vCenter Hyperic Server 5.x (See VMSA-2014-0010 for remediation details)
  • vCenter Infrastructure Navigator 5.x (See VMSA-2014-0010 for remediation details)
  • vCenter Log Insight 1.0, 2.0 (See VMSA-2014-0010 for remediation details)
  • vCenter Operations Manager 5.x (See VMSA-2014-0010 for remediation details)
  • vCenter Orchestrator Appliance 4.x, 5.x (See VMSA-2014-0010 for remediation details)
  • vCenter Server Appliance 5.x (See VMSA-2014-0010 for remediation details)
  • vCenter Site Recovery Manager 5.x (vCenter Site Recovery Manager ships with vSphere Replication and will be re-released with an updated version of this appliance) (See VMSA-2014-0010 for remediation details)
  • vCenter Support Assistant 5.x (See VMSA-2014-0010 for remediation details)
  • vCloud Application Director 5.x, 6.x (aka vFabric Application Director) (See VMSA-2014-0010 for remediation details)
  • vCloud Automation Center 6.x (Note: vCloud Automation Center 5.x is not a virtual appliance) (See VMSA-2014-0010 for remediation details)
  • vCloud Automation Center Application Services 6.x (See VMSA-2014-0010 for remediation details)
  • vCloud Director 5.x Appliance (See VMSA-2014-0010 for remediation details)
  • vCloud Connector 2.x (See VMSA-2014-0010 for remediation details)
  • vCloud Networking and Security 5.x (aka VMware Shield 5.x) (See VMSA-2014-0010 for remediation details)
  • vCloud Usage Meter 3.x (See VMSA-2014-0010 for remediation details)
  • vFabric Postgres 9.x (See VMSA-2014-0010 for remediation details)
  • Viewplanner 3.x
  • VMware Application Dependency Planner
  • VMware Data Recovery 2.x (See VMSA-2014-0010 for remediation details)
  • VMware HealthAnalyzer 5.x
  • VMware Mirage Gateway 5.x (See VMSA-2014-0010 for remediation details)
  • VMware Socialcast On Premise 2.x
  • VMware Studio 2.x
  • VMware Workbench 3.x
  • vSphere App HA 1.x (See VMSA-2014-0010 for remediation details)
  • vSphere Big Data Extensions 1.x, 2.x (See VMSA-2014-0010 for remediation details)
  • vSphere Data Protection 5.x
  • vSphere Management Assistant 5.x (See VMSA-2014-0010 for remediation details)
  • vSphere Replication 5.x (See VMSA-2014-0010 for remediation details)
  • vSphere Storage Appliance 5.x (See VMSA-2014-0010 for remediation details)

Check back this KB on regular basis –  KB 2090740.

Shares
Vote !

| Filed Under: Free Stuff Tagged With: Shellshock, Shellshock bug

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam confirming vSphere 9.0 and ESXi 9 upcoming support
  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in