ALERT BASH Security Vulnerability

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,201
Reaction score
5,221
You ran the Ubuntu update for an ARM-based Beagle Bone on your Intel-based CentOS server?? Really???
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,201
Reaction score
5,221
Try this:
Code:
cd /bin
cp bash.old bash

And then:
Code:
yum update bash
 

Ramblin

Guru
Joined
Oct 28, 2010
Messages
138
Reaction score
9
Try this:
Code:
cd /bin
cp bash.old bash

And then:
Code:
yum update bash
Back to where I was and now I'll do it properly

Thank you

OK, so I had a brain fart

That'll teach me (at least I hope) to not do something to a core system while in a rush doing 10 other things

Thanks again

Richard
 

nievz

New Member
Joined
Dec 2, 2011
Messages
28
Reaction score
1
Guys, do i need to run patch 1 and then patch 2 or just patch 2? Please advice? I'm on centos.
 

nievz

New Member
Joined
Dec 2, 2011
Messages
28
Reaction score
1
Since getting no response on my previous post, I think patch2 is cummulative and i don't need to run patch 1.

Now another thing I'm being asked in the office is if this break the server, is there any way to rollback to previous configuration before the patch? Any change we do for production servers must have a rollback plan. Please let me know, appreciate any response. Thanks!
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,201
Reaction score
5,221
If you want a backup, make a copy of /bin/bash before you apply the update.
 

JimLS

Member
Joined
May 22, 2013
Messages
43
Reaction score
2
steven is correct. BeagleBone Black build of RasPBX (not our product) is using an older version of Ubuntu which is no longer supported. I've compiled all available BASH fixes into a new version of BASH, but the SegFault test still flunks. 4 out of 5 tests pass with this update. We'll keep checking.
I'm confused... Both by the "not our product" and "older version of Ubuntu". Nerdvittles announced the version for BBB. How is this "not our product"? And the current version for BBB uses Ubuntu 14.04 which as far as I can tell IS supported. The bash issue came up with the prior version but from the date of the comments I think the 14.04 version was already out. Just trying to understand...
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,201
Reaction score
5,221
JimLS: "Not our product" means someone else designed, developed and maintains the operating system for RasPBX. Simply put, if there is a problem with the operating system, then responsibility for addressing it rests with the organization that released and maintains RasPBX. Incredible PBX for BBB added applications for Asterisk on top of the existing RasPBX platform.
 

Members online

No members online now.

Forum statistics

Threads
25,812
Messages
167,763
Members
19,241
Latest member
bellabos
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top