NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
skilke
Sep 25, 2014Aspirant
BASH exploit - Shellshock
Hi
I have a ReadyNas Ultra 2 and it has version 3.1.17 of BASH installed which has a High risk vulnerability.
Can somebody please explain how to patch BASH so that my system is not at risk from this vulnerability. I have tried downloading the source, the patch and patching but 1 file did not patch successfully. If anyone can post some step by step instructions it would be really appreciated (as I am not an expert).
Many thanks
K
I have a ReadyNas Ultra 2 and it has version 3.1.17 of BASH installed which has a High risk vulnerability.
Can somebody please explain how to patch BASH so that my system is not at risk from this vulnerability. I have tried downloading the source, the patch and patching but 1 file did not patch successfully. If anyone can post some step by step instructions it would be really appreciated (as I am not an expert).
Many thanks
K
76 Replies
Replies have been turned off for this discussion
- mdgm-ntgrNETGEAR Employee RetiredSkywalker already mentioned some beta builds that have patches for the exploit. Couldn't you just update to the beta?
Or get apt to look at the 4.2.27 repository and try to install the necessary packages from there. - btaroliProdigyAh, OK... I see that here: viewtopic.php?f=51&t=70385
In general, though, it's when patches are delivered as patches and don't require taking a beta OS release to accomplish. :) In my case I'm comfortable with that... but not everyone would be. - mdgm-ntgrNETGEAR Employee RetiredWell if you edited the sources list to use 4.2.27 repository then you probably could install the bash update using apt-get whilst remaining on 4.2.26.
- btaroliProdigyMmm... good point.. and then change it back after to avoid other potential interactions?
- mdgm-ntgrNETGEAR Employee RetiredYes.
Or don't touch the sources list, find the package in the repository, download it and install it via dpkg.
This of course assumes that there aren't other packages that need to be upgraded too. - sorenfriisAspirantI can confirm that changing the /etc/apt/sources.list to the 4.2.27 repository works for my Ultra4.
Here is a quite terrifying example of why we need to take this very seriously:
https://www.trustedsec.com/september-2014/shellshock-dhcp-rce-proof-concept/ - jdgsAspirantI have just managed to resolve this on my ReadyNAS 2100.
Updating apt-get and installing bash didn't help for me in the first instance as apt-get was looking at the 4.2.26 repo. Changed it to 4.2.27 temporarily by editing etc/apt/sources.list and was able to update bash ok. - skilkeAspirantThanks for the firmware update.
- gareth_iowcAspirantReady nas 104 is affected
firmware 6.1.9 - super_poussinVirtuosoapt-get update
apt-get install bash
Envoyé de mon iPhone en utilisant Tapatalk
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!