Unix-based systems, as used worldwide by sysadmins and cloud providers alike, could be hijacked by hackers abusing a hard-coded vuln that allows them to inject arbitrary commands into shell scripts executed by high-privilege users. . A class of vulnerabilities involving so-called wildcards allows a user to affect shell commands issued by other users through filename manipulation. If the other user is a privileged user, such as root, then the tactic could be used to run elevation of privilege-style attacks. The link for this article located at The Register UK is no longer available. . Glob patterns in Unix environments can result in command injection flaws that compromise administrative accounts.. Unix Exploits, Command Injection, Privilege Escalation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.