SSH bash紧急安全补丁!重要!

建站交流11年前 (2014-09-26)15670

漏洞详情页面:http://seclists.org/oss-sec/2014/q3/650

漏洞级别:非常严重

漏洞信息:

1.测试是否存在漏洞,执行以下命令:

  1. env t='() { :;}; echo You are vulnerable.' bash -c "true"

复制代码


如果显示You are vulnerable,很遗憾,必须立即打上安全补丁修复

2.修复漏洞办法 更新来自阿里云的方法:http://bbs.aliyun.com/read/176977.html


  1. centos:

  2. yum -y update bash


  3. ubuntu:

  4. 14.04 64bit

  5. wget http://mirrors.aliyun.com/fix_stuff/bash_4.3-7ubuntu1.1_amd64.deb && dpkg -i bash_4.3-7ubuntu1.1_amd64.deb


  6. 14.04 32bit

  7. wget http://mirrors.aliyun.com/fix_stuff/bash_4.3-7ubuntu1.1_i386.deb && dpkg -i  bash_4.3-7ubuntu1.1_i386.deb



  8. 12.04 64bit

  9. wget http://mirrors.aliyun.com/fix_stuff/bash_4.2-2ubuntu2.2_amd64.deb && dpkg -i  bash_4.2-2ubuntu2.2_amd64.deb


  10. 12.04 32bit

  11. wget http://mirrors.aliyun.com/fix_stuff/bash_4.2-2ubuntu2.2_i386.deb && dpkg -i  bash_4.2-2ubuntu2.2_i386.deb


  12. 10.× 64bit

  13. wget http://mirrors.aliyun.com/fix_stuff/bash_4.1-2ubuntu3.1_amd64.deb && dpkg -i bash_4.1-2ubuntu3.1_amd64.deb


  14. 10.× 32bit

  15. wget http://mirrors.aliyun.com/fix_stuff/bash_4.1-2ubuntu3.1_i386.deb && dpkg -i bash_4.1-2ubuntu3.1_i386.deb



  16. debian:

  17. 7.5 64bit && 32bit

  18. apt-get -y install --only-upgrade bash


  19. 6.0.x 64bit

  20. wget http://mirrors.aliyun.com/debian/pool/main/b/bash/bash_4.1-3%2bdeb6u1_amd64.deb &&  dpkg -i bash_4.1-3+deb6u1_amd64.deb


  21. 6.0.x 32bit

  22. wget http://mirrors.aliyun.com/debian/pool/main/b/bash/bash_4.1-3%2bdeb6u1_i386.deb &&  dpkg -i bash_4.1-3+deb6u1_i386.deb


  23. opensuse:

  24. 13.1 64bit

  25. wget http://mirrors.aliyun.com/fix_stuff/bash-4.2-68.4.1.x86_64.rpm && rpm -Uvh bash-4.2-68.4.1.x86_64.rpm



  26. 13.1 32bit

  27. wget http://mirrors.aliyun.com/fix_stuff/bash-4.2-68.4.1.i586.rpm && rpm -Uvh bash-4.2-68.4.1.i586.rpm


  28. aliyun linux:

  29. 5.x 64bit

  30. wget http://mirrors.aliyun.com/centos/5/updates/x86_64/RPMS/bash-3.2-33.el5.1.x86_64.rpm && rpm -Uvh bash-3.2-33.el5.1.x86_64.rpm


  31. 5.x 32bit

  32. wget http://mirrors.aliyun.com/centos/5/updates/i386/RPMS/bash-3.2-33.el5.1.i386.rpm && rpm -Uvh bash-3.2-33.el5.1.i386.rpm

发表评论

访客

看不清,换一张

◎欢迎参与讨论,请在这里发表您的看法和观点。