perfsonar / project

The perfSONAR project's primary wiki and issue tracker.
Apache License 2.0
54 stars 10 forks source link

Vulnerability : CVE-2014-6271 #984

Closed arlake228 closed 9 years ago

arlake228 commented 9 years ago

Original issue 986 created by arlake228 on 2014-09-26T05:30:48.000Z:

What steps will reproduce the problem?

1.Run test : 2.env x='() { :;}; echo vulnerable' bash -c "echo this is a test" 3.

What is the expected output? What do you see instead?

What version of the product are you using? On what operating system? pS-NPToolkit-3.3.2 [root@localhost ~]# uname -a Linux localhost.localdomain 2.6.32-431.3.1.1.el6.aufs.web100.x86_64 # 1 SMP Fri Feb 7 16:01:34 EST 2014 x86_64 x86_64 x86_64 GNU/Linux

Please provide any additional information below.

Centos has patched this : http://centosnow.blogspot.no/2014/09/critical-bash-updates-for-centos-5.html

Will there be an update to the package, or do we have to run "yum update" ?

Regards Harald Nordås

arlake228 commented 9 years ago

Comment #1 originally posted by arlake228 on 2014-09-26T06:23:15.000Z:

yum update fixed the issue.

When will netinstall image be updated ?

arlake228 commented 9 years ago

Comment #2 originally posted by arlake228 on 2014-09-26T12:02:14.000Z:

The NetInstall image does not need to be updated. By definition it will pulldown the latest packages at install time.

We will rebuild the LiveCD and announce when it's ready. You have to give us at least a few hours especially when patches come out at 11pm EDT :) Hopefully you have been watching the perfsonar-announce and perfsonar-user list where we have been keeping people apprised of the situation for the past few days and already did one LiveCD rebuild for the initial patch.

arlake228 commented 9 years ago

Comment #3 originally posted by arlake228 on 2014-10-02T20:42:09.000Z:

Appears to be taken care of