install bash shell shock patch


Doc ID    SOLN304257
Version:    2.0
Status:    Published
Published date:    20 Mar 2018
Created Date:    06 Feb 2017
Author:   
Ruofeng Zhu
 

Details

Customer want to load Bash Shell Shock patch on  System Platform.
 

Problem Clarification

As per PSN, VSP 6.3.6 has fixed the issue

Cause

n/a

Solution

Customer want to load a patch on VSP, hoping to fix the bash shock vulnerability.

As per PSN027007u, The patch has been included in VSP 6.3.6. Since customer's VSP is 6.3.7, we believe the issue has been fixed.

In order to prove it, we execute a command on VSP: env x='() { :; }; echo vulnerable' bash -c "echo this is a test".

The output is "this is a test" , without "vulnerable", which proves the issue has indeed been fixed. So customer don't need to load a patch.

Additional Relevant Phrases

Adding additional information.

Avaya -- Proprietary. Use pursuant to the terms of your signed agreement or Avaya policy