Bash Vulnerability in Rune Audio

Please report any bug found here

Bash Vulnerability in Rune Audio

Postby NullDev » 25 Sep 2014, 17:56

A major bug in the BASH shell was recently uncovered (CVE-2014-6271 & CVE-2014-7169). One can easily test for the vulnerability by running the following from a BASH prompt:

Code: Select all
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"


If you have the bug, you will get:

Code: Select all
vulnerable
this is a test


Most major distros have patched this issue. I'm currently running 0.2-beta on a BBB and my version is vulnerable. Any idea if/when this will be patched? Is there a way of getting the fix without having to restart from scratch?
NullDev
 
Posts: 16
Joined: 25 Feb 2014, 20:10

Re: Bash Vulnerability in Rune Audio

Postby tux » 25 Sep 2014, 19:02

I assume that with a:

pacman -Sy bash

you will be fine. Latest fix is already in archLinuxarm repositories.
User avatar
tux
 
Posts: 34
Joined: 22 Jan 2014, 23:39
Location: Greece

Re: Bash Vulnerability in Rune Audio

Postby NullDev » 25 Sep 2014, 19:35

That brought in bash-4.3.024-2 along with readline-6.3.006-1 as a dependency. After the update, a quick vulnerability check showed I was good to go. Thank you sir!
NullDev
 
Posts: 16
Joined: 25 Feb 2014, 20:10

Re: Bash Vulnerability in Rune Audio

Postby ACX » 25 Sep 2014, 19:56

It's good that it came out just before the 0.3-beta release, so we are in time to include the upgrade in the final image :)
User avatar
ACX
RuneAudio co-founder
 
Posts: 1692
Joined: 29 Nov 2013, 02:25
Location: Udine, Italy

Re: Bash Vulnerability in Rune Audio

Postby NullDev » 25 Sep 2014, 21:27

As an update, only CVE-2014-6271 has been patched at this point. Everyone is still waiting for a valid fix for CVE-2014-7169. It seems to be a slightly tougher nut to crack (so to speak...).
NullDev
 
Posts: 16
Joined: 25 Feb 2014, 20:10

Re: Bash Vulnerability in Rune Audio

Postby cmh714 » 25 Sep 2014, 22:34

I found a detailed article on how to recompile for a Mac, but I can wait....
cmh714
 
Posts: 470
Joined: 04 May 2014, 03:06

Re: Bash Vulnerability in Rune Audio

Postby tux » 26 Sep 2014, 09:21

Today there's a new update on bash package. You need to repeat the procedure I mentioned in my post above!
User avatar
tux
 
Posts: 34
Joined: 22 Jan 2014, 23:39
Location: Greece

Re: Bash Vulnerability in Rune Audio

Postby Peter » 26 Sep 2014, 11:30

I assume that with a:

pacman -Sy bash

you will be fine. Latest fix is already in archLinuxarm repositories.


Thank you, done - and no longer showing vulnerable.
User avatar
Peter
 
Posts: 64
Joined: 06 Mar 2014, 23:32

Re: Bash Vulnerability in Rune Audio

Postby NullDev » 26 Sep 2014, 18:32

Grabbed the 2nd update as well and it works great. I wish I could get my RasPBX system to patch as easily! Thanks folks.
NullDev
 
Posts: 16
Joined: 25 Feb 2014, 20:10

Re: Bash Vulnerability in Rune Audio

Postby Midnight » 29 Sep 2014, 08:14

IMHO this CVE is not really a problem for a music player in your home LAN. What is the worst thing an attacker could do there? Kill your Runeaudio installation or maybe only the Runeaudio web interface?
User avatar
Midnight
Moderator
 
Posts: 141
Joined: 19 Feb 2014, 14:46

support RuneAudio Donate with PayPal

Next

Return to Bug report

Who is online

Users browsing this forum: No registered users and 4 guests