Sue,
Do VIOS or the HMC run BASH as delivered by IBM? I do not think so, but I
know I'll get the question.
--
Jim Oberholtzer
Chief Technical Architect
Agile Technology Architects
-----Original Message-----
From: MIDRANGE-L [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of Sue
Baker
Sent: Thursday, September 25, 2014 3:34 PM
To: midrange-l@xxxxxxxxxxxx
Subject: "Shellshock" BASH vulnerability
If you have added BASH to your IBM i in PASE, please check the NIST CVE
database for information about a newly discovered vulnerability and then
check with your source for BASH to obtain a fix if necessary.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271
The last update I received from my security focused collegue was
- Power Linux is preparing a rollout including PowerKVM: they
are on alert and new codes should be released in matter of a
few hours.
- AIX team is preparing a rollout of the optional bash product
in the AIX toolbox web site: they are also on alert and new
codes should be released in matter of a few hours too. Here:
http://www-
03.ibm.com/systems/power/software/aix/linux/toolbox/download.htm
l
- IBM i is does not ship bash product and did not involve bash in any
OpenSSH package. However, customers may port bash to run in the PASE
environment.
--
Sue
IBM Americas Advanced Technical Sales Support (ATS) Power Systems Rochester,
MN
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe,
or change list options,
visit:
http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a
moment to review the archives at
http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.