[CentOS] URGENT! Shellshock fix DOES NOT fix the bug on CentOS 5.4

Jessica Blank

jblank at twu.net
Fri Sep 26 20:04:48 UTC 2014


Never mind; false alarm. Apparently, we both had a previous 'echo' file 
sitting around from before.

Best,

Jessica

On Fri, 26 Sep 2014, Jessica Blank wrote:

> Good afternoon!
>
> After applying the latest bash RPM listed at
> http://lists.centos.org/pipermail/centos-announce/2014-September/020594.html 
> :
>
> The fixed RPM (bash-3.2-33.el5_10.4.x86_64.rpm) DOES work just fine on CentOS 
> 5.10. However, it DOES NOT work on CentOS 5.4. That is, bash runs fine, but 
> IS STILL VULNERABLE TO SHELLSHOCK!
>
> Scary screenie at: http://i.imgur.com/yR7sBjV.png
>
> It looks like the released RPM somehow behaves DIFFERENTLY on 5.4 as opposed 
> to 5.10.
>
> This has been validated by one of my coworkers; it's apparently not just me.
>
> Best,
>
> Jessica
>



More information about the CentOS mailing list