• February 23, 2025, 02:02:43 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Shellshock aka "Bash Bug"  (Read 3340 times)

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Shellshock aka "Bash Bug"
« on: September 27, 2014, 08:04:26 AM »

If you have installed Fonz fun_plug (aka FFP), it's time to update the bash command. This is especially so if your NAS is exposed to the Internet.

All bash version from 1.14 through 4.3 are vulnerable to the Shellshock bug. The stock version from FFP-0.7 is v4.1.011 which failed the system vulnerability check stated here. Good news is kylek has compiled v4.3.25 which is able to pass the test.

If you're using uwsiteloader script, you should know where to download the package but for those who doesn't, I have hosted it on Mediafire site.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Shellshock aka "Bash Bug"
« Reply #1 on: October 01, 2014, 10:31:57 AM »

Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.