NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
skilke
Sep 25, 2014Aspirant
BASH exploit - Shellshock
Hi I have a ReadyNas Ultra 2 and it has version 3.1.17 of BASH installed which has a High risk vulnerability. Can somebody please explain how to patch BASH so that my system is not at risk from...
wifiuk
Oct 11, 2014Aspirant
Ive read the posts, and i wanted to know after i have done a apt-get update and an apt-get install bash on my Netgear ReadyNAS Duo V2 i get the following errors
And so i type in apt-get install bash anyway and i get this
but i am still vulnerable
could anyone lend a hand please?
Reading package lists... Done
W: A error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://ftp.us.debian.org squeeze-updates Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 8B48AXXXXXX25553 (edited)
W: Failed to fetch http://ftp.us.debian.org/debian/dists/squeeze-updates/Release
W: Some index files failed to download, they have been ignored, or old ones used instead.
And so i type in apt-get install bash anyway and i get this
bash is already the newest version.
You might want to run 'apt-get -f install' to correct these:
The following packages have unmet dependencies:
libidn11-dev : Depends: pkg-config but it is not going to be installed
libncurses5-dev : Depends: libc-dev
libncursesw5-dev : Depends: libc-dev
tzdata-java : Depends: tzdata (= 2012g-0squeeze1) but 2012c-0squeeze1 is to be installed
E: Unmet dependencies. Try 'apt-get -f install' with no packages (or specify a solution).
but i am still vulnerable
root@XXXXXXXXXXXXXX:~# env 'x=() { :;}; echo vulnerable' 'BASH_FUNC_x()=() { :;}; echo vulnerable' bash -c "echo test"
vulnerable
bash: BASH_FUNC_x(): line 0: syntax error near unexpected token `)'
bash: BASH_FUNC_x(): line 0: `BASH_FUNC_x() () { :;}; echo vulnerable'
bash: error importing function definition for `BASH_FUNC_x'
test
root@XXXXXXXXXXXXXX:~#
root@XXXXXXXXXXXXXX~# bash -version
GNU bash, version 4.1.5(1)-release (arm-unknown-linux-gnueabi)
Copyright (C) 2009 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software; you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
could anyone lend a hand please?
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!