Re: [Astlinux-users] Bash vulnerability

2014-09-26 Thread Michael Knill
Thanks guys. I will let my customers know. Regards Michael Knill On 27 Sep 2014, at 9:28 am, Darrick Hartman wrote: We're working on a fix. The risk is minimal as we don't publish some of the ENV variables that are required to use the exploit to it's fullest extent. Darrick Sent from my

Re: [Astlinux-users] Bash vulnerability

2014-09-26 Thread Darrick Hartman
We're working on a fix. The risk is minimal as we don't publish some of the ENV variables that are required to use the exploit to it's fullest extent. Darrick Sent from my mobile device. Please excuse my brevity. -Original Message- From: Michael Knill [michael.kn...@ipcsolutions.com.au]

Re: [Astlinux-users] Bash vulnerability

2014-09-26 Thread Lonnie Abelbeck
Hi Michael, In general, it looks like AstLinux is secure against "Shellshock", given a couple days of investigating. Though, without getting into details, a custom DHCP configuration could possibly be exploited given malicious DHCP endpoints. We are busy preparing AstLinux 1.2.0 with the bash