[SAC] [OSGeo] #1412: Remote Code Execution via BASH Vulnerability

Martin Spott Martin.Spott at mgras.net
Thu Sep 25 01:06:51 PDT 2014


On Thu, Sep 25, 2014 at 10:02:42AM +0200, Markus Neteler wrote:
> On Thu, Sep 25, 2014 at 10:01 AM, Martin Spott <Martin.Spott at mgras.net> wrote:
> > On Thu, Sep 25, 2014 at 12:04:09AM -0000, OSGeo wrote:
> >
> >>  All public-facing OSGeo machines need to be checked for this
> >
> > Already in progress,
> 
> I walked through all machines I know :-)

Same here, but ....

> PS: Not sure if the lenny etc boxes still get that update (if needed there)

No, as far as I know they won't (I'll check again) - and in order for
the "squeeze" boxes to get it, you need to include the "squeeze-lts"
repository.  That's what I'm doing.

Cheers,
	Martin.
-- 
 Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------


More information about the Sac mailing list