NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

skilke's avatar
skilke
Aspirant
Sep 25, 2014

BASH exploit - Shellshock

Hi

I have a ReadyNas Ultra 2 and it has version 3.1.17 of BASH installed which has a High risk vulnerability.

Can somebody please explain how to patch BASH so that my system is not at risk from this vulnerability. I have tried downloading the source, the patch and patching but 1 file did not patch successfully. If anyone can post some step by step instructions it would be really appreciated (as I am not an expert).

Many thanks

K

76 Replies

Replies have been turned off for this discussion
  • mdgm-ntgr's avatar
    mdgm-ntgr
    NETGEAR Employee Retired
    Perhaps edit your sources list to comment the relevant line then try again.
  • which source do i need to add for the Ready Nas Duo v2

    i have this




    # deb http://ftp.us.debian.org/debian/ squeeze main

    deb http://ftp.us.debian.org/debian/ squeeze main
    deb-src http://ftp.us.debian.org/debian/ squeeze main

    deb http://security.debian.org/ squeeze/updates main
    deb-src http://security.debian.org/ squeeze/updates main

    deb http://ftp.us.debian.org/debian/ squeeze-updates main
    deb-src http://ftp.us.debian.org/debian/ squeeze-updates main
    ~
    ~



  • mdgm-ntgr's avatar
    mdgm-ntgr
    NETGEAR Employee Retired
    Comment the last two lines?

    What did you do with the lines for the ReadyNAS apt-get repository?
  • mdgm-ntgr's avatar
    mdgm-ntgr
    NETGEAR Employee Retired
    O.K.

    Add

    deb http://www.readynas.com/packages 5.3.11/
  • nice one that has resolved the


    env 'x=() { :;}; echo vulnerable' 'BASH_FUNC_x()=() { :;}; echo vulnerable' bash -c "echo test"




    bash: warning: x: ignoring function definition attempt
    bash: error importing function definition for `BASH_FUNC_x'
    test

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More