[Dorset] BASH security vulnerability

2014-09-25 Thread Paul Stenning
Hi all, Please be aware of a serious security vulnerability that has been discovered in BASH. I received notification of this from a web hosting company I use regarding CentOS but it applies to all Linux distros. Please update ASAP, especially web servers etc. Below is the message they se

Re: [Dorset] BASH security vulnerability

2014-09-25 Thread Martin Hepworth
Centos/RH fix not 100% complete and you'll have to do this again. also check if your web servers are running cgi scripts as bash scripts this is a bigger problem in general as it's prone to alsorts of abuse -- Martin Hepworth, CISSP Oxford, UK On 25 September 2014 13:30, Paul Stenning wro

Re: [Dorset] BASH security vulnerability

2014-09-25 Thread Terry Coles
On Thursday 25 Sep 2014 16:38:03 Martin Hepworth wrote: > Centos/RH fix not 100% complete and you'll have to do this again. > > also check if your web servers are running cgi scripts as bash scripts > this is a bigger problem in general as it's prone to alsorts of abuse The real problem with

Re: [Dorset] BASH security vulnerability

2014-09-25 Thread Ralph Corderoy
Hi Terry, > There must be millions of similar devices out there, eg TVs, routers, > network storage, fridges even. Whose going to sort them out? The machine has to be running bash; lots of smaller devices run a lighter shell, e.g. dash, or Busybox. And to be vulnerable, there has to be a means

Re: [Dorset] BASH security vulnerability

2014-09-25 Thread Terry Coles
On Thursday 25 Sep 2014 16:58:31 Ralph Corderoy wrote: > > There must be millions of similar devices out there, eg TVs, routers, > > network storage, fridges even. Whose going to sort them out? > > The machine has to be running bash; lots of smaller devices run a > lighter shell, e.g. dash, or B

Re: [Dorset] BASH security vulnerability

2014-09-26 Thread Paul Stenning
A further update has been released by RedHat in the last few hours. WHM/cPanel based webservers that I manage which check for updates at around 4am did not get the latest update, but it was available when I checked manually this morning. As the default update checking time is between midnight

Re: [Dorset] BASH security vulnerability

2014-09-26 Thread Peter Merchant
On 26/09/14 09:10, Paul Stenning wrote: A further update has been released by RedHat in the last few hours. WHM/cPanel based webservers that I manage which check for updates at around 4am did not get the latest update, but it was available when I checked manually this morning. As the default