Bash Vulnerability

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • richa164
    replied
    That is it im afraid , you are vulnerable on the servers you have run the command on , await further updates and patches for supported hardware.

    Leave a comment:


  • audetd
    replied
    Originally posted by jaytarbox View Post
    Patches out for various CM versions now, no indication if they're service interrupting or not.
    I have install on CM 6.2 Via Platform and this is HOT not service affecting

    See my screen capture in attachement
    Attached Files

    Leave a comment:


  • jaytarbox
    replied
    Was it service interrupting when you installed it?

    Leave a comment:


  • audetd
    replied
    I have installed the 6.2 patch in my Lab and the script test does not show the Vulnerable word any more.

    But Platform still show it. so we will need patch later on this one.

    Here is the link where i got the patch.

    Last edited by audetd; 10-02-2014, 04:37 PM.

    Leave a comment:


  • jaytarbox
    replied
    Patches out for various CM versions now, no indication if they're service interrupting or not.

    Leave a comment:


  • alb293
    replied
    Yes, if the code above does not return Vulnerable, you are fine.

    Leave a comment:


  • audetd
    replied
    Originally posted by richa164 View Post
    Run this test from linux shell.







    env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

    If you get

    Vulnerable
    This is a test

    Well guess what !!


    and now just checking my LAB's

    Here is the result for the Communication Manager
    dadmin@CM-LAB> env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
    vulnerable
    this is a test

    Result for my DOM0
    [admin@CM2-SPDom0 ~]$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
    vulnerable
    this is a test
    [admin@CM2-SPDom0 ~]$

    Result for my CDOM0
    [admin@CM2-SPCdom ~]$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
    vulnerable
    this is a test
    [admin@CM2-SPCdom ~]$


    So that mean i am Vulnerable.

    is there an offcial procedure from Avaya to find out.

    Daniel
    Last edited by audetd; 10-02-2014, 12:27 PM.

    Leave a comment:


  • richa164
    replied
    Run this test from linux shell.







    env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

    If you get

    Vulnerable
    This is a test

    Well guess what !!

    Leave a comment:


  • jlm
    replied
    Does anyone happen to know if this affects IP phones, and in particular the 9600 series (9608, 9611, etc.) that run a linux kernel?

    I don't see this addressed on the Avaya shellshock info.

    Regards,

    - Joe

    Leave a comment:


  • aa1
    replied
    Asa-2014-369

    Take a look at this:



    Arbi

    Leave a comment:


  • jaytarbox
    replied
    You should wait, most of the products you wouldn't have the rights to install the needed patch anyway.

    Leave a comment:


  • darrenspain
    replied
    hi
    are avaya telling the customers to wait until they have included updates in patchs / security updates or are avaya telling customers to go ahead and use the updates from the RedHat site ?

    I have read the bulletin from Avaya but it is not clear to me what is the recommended course of action ?

    Thanks
    Darren

    Leave a comment:


  • rbrookes
    replied
    Shellshock/Bash impact update for Avaya products
    Avaya’s Product Security Team is aware of the Shellshock security issue and is working aggressively with product teams across our portfolio to assess any possible impact and identify a mitigation plan as appropriate. An Avaya Security Advisory (ASA) will be published later today, Friday 26 September at approximately 7pm ET. The Product Security team will continue to report findings as they become available.

    Please visit the following link on the Avaya Support Website for the latest information on this topic. All ASAs for Shellshock will be posted to this site.

    Avaya Support Website – Shellshock/Bash Impact for Avaya Products - https://support.avaya.com/helpcenter...26131554370002

    Leave a comment:


  • tkbinpdx
    replied
    Avaya Advisory link for 2014 - nothing posted since 9/23

    Leave a comment:


  • jaytarbox
    replied
    And, Avaya hasn't said a word that I can find yet. I had customers asking about it only a few hours after the news broke.
    Last edited by jaytarbox; 09-26-2014, 08:28 AM.

    Leave a comment:

Loading