站長資訊網
最全最豐富的資訊網站

CentOS如何升級Bash(修復破殼漏洞)

下面由centos教程欄目給大家介紹CentOS 升級 Bash — 修復破殼漏洞 ,希望對需要的朋友有所幫助!

CentOS如何升級Bash(修復破殼漏洞)

因為很多公司都有自己的 yum 源,所以直接配置其他的 yum 源升級的話是不允許的,為了能方便的升級,并且安全的測試,先拿一臺測試機做測試。

CentOS 的修復方案

安裝 yum 插件 yum-downloadonly

注: yum-downloadonly 插件的作用是實現只下載所需包而不直接安裝

sudo yum -y install yum-downloadonly

添加 CentOS 的官方源 CentOS-Base.repo

CentOS 5 的官方源

# CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5

CentOS 6 的官方源

# CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6

下載最新的 bash 包

把最新版本的 bash 的 rpm 包下載到 /tmp 目錄

sudo  yum -y install --downloadonly --downloaddir=/tmp/ bash

下載后的包名分別如下:

CentOS 5

bash-3.2-33.el5_10.4.x86_64.rpm

CentOS 6

bash-4.1.2-15.el6_5.2.x86_64.rpm

安裝最新的 bash 包

CentOS 5

sudo yum -y install bash-3.2-33.el5_10.4.x86_64.rpm

CentOS 6

sudo yum -y install bash-4.1.2-15.el6_5.2.x86_64.rpm

驗證

env X='() { (a)=>' sh -c "echo date"; cat echo 輸出如下:

date Mon Sep 29 10:11:56 CST 2014

env VAR='() { :;}; echo Bash is vulnerable!' bash -c "echo Bash Hello" 輸出如下:

Bash Hello

證明修復成功

加入現有的 rpm 源

最后一步就是把測試完成的包加入公司自己的源中,然后全網推送了。

贊(0)
分享到: 更多 (0)
網站地圖   滬ICP備18035694號-2    滬公網安備31011702889846號
亚洲福利一区二区精品秒拍| 亚洲精品国产品国语在线| 国产精品毛片AV久久66| 国产精品成人va| 91在线精品中文字幕| 日韩精品无码中文字幕一区二区| 青草青草久热精品视频在线网站| 91精品国产9l久久久久| 国产色精品vr一区区三区| 亚洲精品国精品久久99热| 一区二区不卡久久精品| 亚洲AV成人精品日韩一区18p| 日韩午夜在线视频不卡片| 欧美日韩久久久精品A片| 国产亚洲日韩一区二区三区| 国产亚洲精品美女久久久久| 国产精品李雅在线观看| 精品久久免费视频| 日本三区精品三级在线电影| 精品亚洲国产成人av| 久久久一本精品99久久精品36| 亚洲精品9999久久久久无码| 人妻少妇精品无码专区漫画| 久久99精品久久久久久水蜜桃| www.国产精品.com| 老司机在线精品视频| 国产精品久久久久久久app| 国产美女在线精品观看| 精品视频一区二区三区四区| 亚洲精品9999久久久久无码| 精品国产天堂综合一区在线| 国产精品无码av片在线观看播| 国产免费69成人精品视频| 国产成人啪精品视频免费网| 四虎精品久久久久影院| 亚洲AV日韩精品久久久久久久| 日韩精品福利片午夜免费观着| 污污网站国产精品白丝袜| 国产玖玖玖九九精品视频| 久久青青草原精品国产不卡| 国产精品亚洲片在线|