Koozali.org: home of the SME Server

[SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory

guest22

[SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« on: September 25, 2014, 12:21:31 AM »
As per advisory explained here:

http://lists.centos.org/pipermail/centos/2014-September/146099.html

a fix has been made available for both SME8 and SME9.

You are advised to perform a 'yum update'  immediately.

[ I UPDATE SEPT 26 2014]
It seems that the above mentioned fix did not resolve the issue 100%.

https://access.redhat.com/security/cve/CVE-2014-7169

Please check the CentOS announcements for upcoming updates.

II UPDATE SEPT 26 2014
Upstream has released a new Bash package. This new package fixes the vulnerability as described here:

http://lists.centos.org/pipermail/centos/2014-September/146176.html

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #1 on: September 27, 2014, 08:48:26 PM »
I've one server running x64 SME 8 and one running i386 SME 8. The updates have appeared on the x64 box, but not the i386. Has anyone else found this?
Jim

guest22

Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #2 on: September 27, 2014, 08:56:44 PM »
I've one server running x64 SME 8 and one running i386 SME 8. The updates have appeared on the x64 box, but not the i386. Has anyone else found this?

The output on that box from 'rpm -q bash' should be 'bash-3.2-33.el5_10.4.i386'

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #3 on: September 27, 2014, 09:05:37 PM »
OK, will check it. Thanks.
Jim

Offline janet

  • ****
  • 4,812
  • +0/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #4 on: September 28, 2014, 01:48:10 AM »
Peasant

My i386 box reports the bash update OK.
Do you have update reporting configured in server manager, & for the same frequency ?
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #5 on: September 28, 2014, 11:49:59 PM »
Think I may have found the problem. The CentOS and CentOS updates repositories are disabled on the i386 box, but enabled on the x64 box. I am assuming they should be enabled on both machines?

Jim

Offline janet

  • ****
  • 4,812
  • +0/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #6 on: September 29, 2014, 01:18:42 AM »
Peasant

Yes
Was the 386 box updated from sme7 ?
To be sure you can reset all repos to standard defaults, see FAQ,, link at top of forums or here
http://wiki.contribs.org/SME_Server:Adding_Software#Restoring_Default_Yum_Repositories
« Last Edit: September 29, 2014, 01:26:42 AM by janet »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #7 on: September 29, 2014, 09:59:54 AM »
Thanks.

Both machines were a clean install and then a restore from a v7 backup via server manager. However since then the x64 machine has had another clean install and restore from backup due to hardware failure.

Looking at bash history, on both machines at some point I've run a command that disables the base and updates repos. I've a feeling it was to do with a bug, but I can't remember what exactly it was. The x64 machine's hardware failure was relatively recent so that is probably why all the repos are enabled in it.

Both machines are at different sites and are not connected.
Jim

guest22

Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #8 on: September 29, 2014, 10:43:24 AM »
Looking at bash history, on both machines at some point I've run a command that disables the base and updates repos. I've a feeling it was to do with a bug, but I can't remember what exactly it was.

Maybe a tip, you can add comments to your shell commands e.g.:

cat /etc/redhat-release #Check what version we are running

or

db yum_repositories setprop base status disabled # disable the base repo due to some bug, before enabling please check issue #12345 @Peasant

bash history will show your comments.

guest

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #9 on: September 29, 2014, 10:47:19 AM »
Quote
Maybe a tip, you can add comments to your shell commands e.g.:

Very useful, thanks for that.
Jim

Offline Peasant

  • *
  • 143
  • +2/-0
Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #10 on: September 29, 2014, 10:23:04 PM »
Quote
The output on that box from 'rpm -q bash' should be 'bash-3.2-33.el5_10.4.i386'

All as it should be now thanks.
Jim

guest22

Re: [SOLVED] [UPDATE SEPT 26] Upstream immediate Security advisory
« Reply #11 on: September 29, 2014, 10:31:23 PM »
Thanks for the feedback and closure of your issue Jim.