[Security] Update bash *NOW*

David Mason dmason-bqArmZWzea/GcjXNFnLQ/w at public.gmane.org
Sun Sep 28 14:53:20 UTC 2014


On 26 September 2014 17:02, Lennart Sorensen
<lsorense-1wCw9BSqJbv44Nm34jS7GywD8/FfD2ys at public.gmane.org> wrote:

> To work around that (other than installing a fixed bash), make sure none
> of the scripts your dhcp client runs use '#!/bin/bash', which at least
> in debian they do by default.  Also make sure /bin/sh is not bash (which
> at least on Debian it hasn't been by default for years).

I thought I was safe because I don't use CGIs, but I use SSI heavily -
same problem.

If you're not lucky enough to run Debian or Ubuntu, you can install
dash and link /bin/sh to it.  That solved my problem on MacOSX where
we're still waiting for an Apple patch (I'm actually much happier with
dash being /bin/sh).

../Dave
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists





More information about the Legacy mailing list