Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: October 01, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
See the following URL for more information from the vendor.
The Avaya Communications Server (CS) 1000 Rls 6 has been reported to be vulnerable.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 26, 2014
Statement Date: September 26, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: September 26, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
https://cygwin.com/ml/cygwin-announce/2014-09/msg00033.html
Notified: September 25, 2014 Updated: September 27, 2014
Statement Date: September 25, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Dell KACE systems use Bash.
Notified: September 25, 2014 Updated: October 07, 2014
Affected
All D-Link Devices and Software have been cleared and are not affected by this vulnerability. All D-Link Services have been audited for the use of bash shell implementations. Based on the results of the audit we have applied appropriate updates, if needed, to close this potential vulnerability. D-Link continues to monitor CERT incase of further issues are reported about the Bash Shell. (Edited: 10/06/2014 15:52 PST)
Please contact at: security@dlink.com
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: October 01, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 26, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Updated: October 02, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 26, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 26, 2014
Statement Date: September 25, 2014
Not Affected
Currently we have already patched CVE-2014-6271 and CVE-2014-7169 in the FreeBSD ports tree, making it no longer vulnerable to these two issues. We will patch the new issues once the fix is validated. The FreeBSD base system do not use bash at all and is therefore not affected.
We are not aware of further vendor information regarding this vulnerability.
FreeBSD has disabled function importing by default in the Bash port.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: October 01, 2014
Not Affected
GTA firewalls running any version of GB-OS are not vulnerable to the "shellshock" exploit.
We are not aware of further vendor information regarding this vulnerability.
Updated: September 25, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
See the following URL for more information from the vendor.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
AIX Toolbox for Linux Applications provides Bash and is vulnerable. IBM HTTP Server (IHS) is based on Apache and may act as an attack vector, depending on configuration.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Statement Date: September 25, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: October 07, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: October 10, 2014
Not Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Updated: October 02, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
DASDEC-1EN running software version 2.0-2 reported to be vulnerable: http://seclists.org/fulldisclosure/2014/Sep/107.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: October 27, 2014 Updated: October 27, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: October 07, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
See the following URL for more information from the vendor
Notified: September 25, 2014 Updated: September 26, 2014
Not Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: November 10, 2014 Updated: November 11, 2014
Affected
Information contained below is subject to change due to the evolving nature of CVE-reported information & available fixes. "ShellShock" CVE-2014-6271 & CVE-2014-7169 are now resolved in software patches made available via NIKSUN SupportNet. NIKSUN has now produced software updates for all supported product lines. We continue to observe activity on the NSON (NIKSUN Security Observation Network) to produce current threat detections – more signatures may be released as we continuously observe behavior globally. Current signatures should be downloaded & installed, available via SupportNet, to get the most out of your NIKSUN security products. The BASH component defect affecting the community-at-large is serious, but unlike the Heartbleed defect, which generically affected many publically available products in exactly the same way, Shellshock requires a specific set of conditions to exist for exploitation. NIKSUN is both a contributor to the open source community as well as a consumer and is leveraging those relationships to bring this issue to a satisfactory close. "ShellShock" CVE-2014-6271 & CVE-2014-7169 are now resolved in software patches made available via NIKSUN SupportNet. NIKSUN has now produced software updates for all supported product lines, with additional work in progress on breaking CVEs related to ShellShock exposed in the last few days – software currently in a quality assurance cycle will become available this week for remaining CVEs associated with ShellShock now that the global community has agreed on a sustainable, supportable fix. We continue to observe activity on the NSON (NIKSUN Security Observation Network) to produce current threat detections with more signatures released as we continuously observe behavior globally. Current signatures should be downloaded & installed, available via SupportNet, to get the most out of your NIKSUN security products. NIKSUN is committed to providing a rapid resolution to this issue while ensuring quality, stability & completeness of a fix. The list below is not a fully comprehensive version list NIKOS Appliance 4.3.2.0 NIKOS Appliance 4.3.1.2 NIKOS Appliance 4.4.1.1 NIKOS Appliance 4.4.1.2 NIKOS Appliance 4.5.0.0_9 NIKOS Appliance 4.5.0.1 NetOmni 4.3.1.2 NetOmni 4.3.2.0 NetOmni 4.4.1.1 NetOmni 4.4.1.2 NetOmni 4.5.0.0 NetOmni 4.5.0.1 NetOmni 4.5.1.0
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Solaris includes Bash and Oracle Linux is based on Red Hat Linux.
Notified: September 25, 2014 Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
See PAN-SA-2012-000{2,3,4,5}. Please use CVE.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: April 14, 2015
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Statement Date: September 25, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: September 27, 2014
Affected
As far as we are aware, none of Sophos's Linux or UNIX products use Bash in a way that would allow this vulnerability to be exploited with data supplied by an attacker from outside.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: November 19, 2014 Updated: November 19, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 29, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 27, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.
Updated: October 01, 2014
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
Notified: September 25, 2014 Updated: September 25, 2014
Unknown
No statement is currently available from the vendor regarding this vulnerability.