{"id":1474,"date":"2014-09-26T12:04:32","date_gmt":"2014-09-26T11:04:32","guid":{"rendered":"http:\/\/blog.cloud-client.info\/?p=1474"},"modified":"2014-10-03T14:04:06","modified_gmt":"2014-10-03T13:04:06","slug":"info-igel-linux-and-shellshock-security-issue","status":"publish","type":"post","link":"https:\/\/blog.cloud-client.info\/?p=1474","title":{"rendered":"Info (updated): IGEL Linux and Shellshock security issue"},"content":{"rendered":"<div class=\"f1b57b4156f3c43e8a7d72dffc4b2e52\" data-index=\"1\" style=\"float: none; margin:10px 0 10px 0; text-align:center;\">\n<script type=\"text\/javascript\"><!--\r\ngoogle_ad_client = \"ca-pub-5449811010861855\";\r\n\/* blog.cloud-client.info 2 *\/\r\ngoogle_ad_slot = \"6689524735\";\r\ngoogle_ad_width = 468;\r\ngoogle_ad_height = 60;\r\n\/\/-->\r\n<\/script>\r\n<script type=\"text\/javascript\"\r\nsrc=\"http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\">\r\n<\/script>\n<\/div>\n<p>Hello Folks,<\/p>\n<p>already a few days the Linux\/MacOSX Shellshock issue is sneaking around the internet, one question: Is the IGEL Linux affected?<\/p>\n<p>Here is the answer: Yes<\/p>\n<p>All IGEL Linux Version up to Firmware 5.04.100 have a Bash Version lower than 4.3 installed, means all these systems are affected.<\/p>\n<p>You can check this quite easy with the command &#8220;bash &#8211;version&#8221;<\/p>\n<p>or enter the following comand in a Terminal Session:<\/p>\n<blockquote><p><em>test=&#8221;() { echo Hello; }; echo Hacked&#8221; bash -c &#8220;&#8221;<\/em><\/p><\/blockquote>\n<p>Is it critical? Depends on your configuration, by default the IGEL System is very secure and the regular user don&#8217;t have any option to gain access to the command line or to a configuration to enter these &#8220;variable&#8221; hacks. So as long the user can not access the command line nothing will happen, there is no webserver or similar to sneak in with some dirty &#8220;cheats&#8221;.<\/p>\n<p>So we classify this issue as &#8220;Low&#8221; for a regular configured IGEL Linux based Thin Client.<\/p>\n<p>I will update you and provide a fix asap for the x86 based Linux (iam sorry but i don&#8217;t have a ARM\u00a0platform to provide a ARM compiled bash replacement), these fix can be used until IGEL will release a firmware update to fix this issue.<\/p>\n<p>Update: IGEL has released fixed firmwares for all current devices.<\/p>\n<p>Cheers<\/p>\n<p>Michael<\/p>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Hello Folks, already a few days the Linux\/MacOSX Shellshock issue is sneaking around the internet, one question: Is the IGEL Linux affected? Here is the answer: Yes All IGEL Linux Version up to Firmware 5.04.100 have a Bash Version lower than 4.3 installed, means all these systems are affected. You can check this quite easy [&hellip;]<\/p>\n","protected":false},"author":1423,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[20,15,7],"tags":[],"class_list":["post-1474","post","type-post","status-publish","format-standard","hentry","category-lxarm","category-udlsos","category-solutions"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p3AZQ3-nM","_links":{"self":[{"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/posts\/1474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/users\/1423"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1474"}],"version-history":[{"count":4,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/posts\/1474\/revisions"}],"predecessor-version":[{"id":1495,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=\/wp\/v2\/posts\/1474\/revisions\/1495"}],"wp:attachment":[{"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cloud-client.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}