Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
alo
May 1, 2005


Fat Dallas posted:

This vulnerability only affects the following version of BASH:

bash-4.2.45-5.el7_0.2
bash-4.1.2-15.el6_5.1
bash-4.1.2-15.el6_5.1.sjis.1
bash-4.1.2-9.el6_2.1
bash-4.1.2-15.el6_4.1
bash-3.2-33.el5.1
bash-3.2-33.el5_11.1.sjis.1
bash-3.2-24.el5_6.1
bash-3.2-32.el5_9.2
bash-3.0-27.el4.2

And uh... everything earlier too.

Adbot
ADBOT LOVES YOU

alo
May 1, 2005


ukle posted:

It also affects Busybox as well, which is where the first seen in the wild use of this exploit was found.

I don't believe this is true (I hope).

Fat Dallas posted:

Fair point... But if you're running anything earlier than v.3.0, then you have bigger problems.

Which is why this is kind of a big thing in the long term for older appliances that will never see anything newer than bash 2.95. A lot of older appliances that are connected to the Internet are just going to keep connecting to botnets until their power supplies die.

The heartbleed vulnerability was limited to a 2 year window. Almost every appliance affected was still vendor supported.

alo
May 1, 2005


Debian has released a package (for stable).

https://security-tracker.debian.org/tracker/CVE-2014-7169

  • Locked thread