AWS EC2: Updated AMIs for Wheezy 7.6, Jessie snapshots for 2014-6271 (Bash/shellshock)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hello all,
Following the recent "bash bug" of CVE CVE-2014-6271 and CVE-2014-7169,
I have generated fresh AMIs for EC2 that should contain the updated
bash package. These new AMIs are in all Regions, including Bejing and
US-GovCloud, and are for Wheezy 7.6 (tagged now as 7.6.aws.1), and
Jessie (date stamped 20140925).
Any instances currently running should apply pending security updates
(apt-get update && apt-get upgrade), configure automatic updates
(apt-get install unattended-upgrades), or be replaced by new instances
from updated AMIs.
S3-backed Wheezy and Squeeze AMIs are pending. The Wheezy 7.6 pmv
i386 and amd64 are being pushed to the AWS marketplace shortly.
The following is a list of Wheezy 7.6 AMIs:
Region | EBS PVM i386 | EBS PVM amd64 | EBS HVM amd64
============================================================
us-east-1 ami-ce40f5a6 ami-f241f49a ami-0c249164
ap-northeast-1 ami-c5123bc4 ami-b1123bb0 ami-c9e3cac8
eu-west-1 ami-f2f05185 ami-46f05131 ami-94fe5fe3
ap-southeast-1 ami-f86d4aaa ami-cc6d4a9e ami-90684fc2
ap-southeast-2 ami-27fb981d ami-31fb980b ami-7dfe9d47
us-west-2 ami-ad90d39d ami-5f90d36f ami-259dde15
us-west-1 ami-8dd1d9c8 ami-f9d1d9bc ami-55d7df10
sa-east-1 ami-e70aa0fa ami-e90aa0f4 ami-0508a218
cn-north-1 - ami-de55c7e7 -
us-gov-west-1 ami-dfd8bffc ami-cfd8bfec ami-d3d8bff0
https://wiki.debian.org/Cloud/AmazonEC2Image/Wheezy
For Jessie AMIs:
Region | EBS HVM amd64
============================
eu-west-1 ami-c4f859b3
sa-east-1 ami-9f0ba182
us-east-1 ami-d83782b0
ap-northeast-1 ami-13eac312
us-west-2 ami-419ad971
us-west-1 ami-89d4dccc
ap-southeast-1 ami-1e6a4d4c
ap-southeast-2 ami-41f99a7b
cn-north-1 ami-d255c7eb
us-gov-west-1 ami-2f26400c
https://wiki.debian.org/Cloud/AmazonEC2Image/Jessie
Any CloudFormation templates and/or AutoScale groups that reference
these deprecated AMIs should be updated to use newer AMIs. If you wish
to preserve these images yourself, you may launch an instance from these
AMIs, then create a new AMI of the running instance saved in your
account to keep it. Note that you will start paying for the storage of
the snapshot (for EBS backed AMIs) or S3 storage (for S3 backed AMIs)
corresponding to the instance at the time you create your own image.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBCAAGBQJUJR+gAAoJEK7IKHSdhcU8rjEQAIiKohmhoy9fd5YnsIGDiDX4
eEuTMiYz5rz/MPz57x3mGOrCGQVn0zDatcuR+b6qVno5rXc69kzL9C23pXJwNXyA
bvlAGqn9zSd/qCAvmqi7L9x0EooWaq5lB/eHvQEqo0Hk9klvAHaBEpSvY9bWQ43P
MjPOwy4r77k/SXzsfJ5Vvl17jm7B8qIroaiYsbRmhgTusSfnwlHacWrUGV9/xFbX
bt+UuDudGU9EZB/3mZhx7HZeGBtdbzmaPGJIPTEW2irE2mXodJ/d+ZiTn1wDJIo+
+0yUr6PmueSZiFIEPpVqaRKhgGelbrA4HN2g+M1axI5hw/06OOVPPKXLHqi/XLvS
/SvdMZSNebXr4x4JzgK26MzCODT3uGJiMnKn7zYfhaWgyRP6hgDvf5nrxb27CiLA
Umvsc/Hm/Nl3Y54uhA88KoiQkh0IJp5uImggjhj9K39qH03bOEj8HKH0N3vOYrBf
MNrLscJQcXznRt3IeVdSo2x6CY7hGyVi3GhACkEEEEWcKh+i3j0goHRUM+9KjqyI
+En5Nx2Yrfn661XKPp60yDFu+xGemErX3JjS2DTCf+YtfruJcYnKREvbjPMzNlt2
hbnIAh3xgjY6yW+nAeLIriF1GcXI90ZwfghdUtPdXGQ+7vTOQ59MMFkGnw16YOkf
+ZXpCJrISYEYdzOyASv9
=sTpS
-----END PGP SIGNATURE-----
Reply to: