[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [BUG]Shellshock



On Sun, Mar 22, 2015 at 01:04:40PM -0300, Thiago Zoroastro wrote:
> Obrigado ao Antonio Terceiro por lembrar que o Debian LTS existe. Estou
> com gNewSense e com algumas dúvidas
> 
> Coloquei no terminal:
> root@root# env x='() { :;}; echo vulneravel' bash -c 'true'
> vulneravel
> root@root# env x='() { :;}; echo unvulneravel' bash -c 'false'
> unvulneravel
> root@root# env x='() { :;}; echo unvulneravel' bash -c 'true'
> unvulneravel
> 
> Coloquei as linhas do Debian LTS sem contrib e non-free. Sources.list:
> 
>         deb http://ftp.at.debian.org/debian-backports/ squeeze-backports
>         main
>         deb http://ftp.de.debian.org/debian squeeze main
> 
> 
>         ## LTS
>         deb http://http.debian.net/debian/ squeeze-lts main
>         deb-src http://http.debian.net/debian/ squeeze-lts main
> 
>         deb http://http.debian.net/debian/ squeeze main
>         deb-src http://http.debian.net/debian/ squeeze main
> 
>         deb http://http.debian.net/debian squeeze-lts main
>         deb-src http://http.debian.net/debian squeeze-lts main
>         # LTS
> 
>         # deb cdrom:[gNewSense 3.0 _Parkes_ - Official i386 LIVE/INSTALL
>         Binary 20140205-19:57]/ parkes main
> 
>         # deb cdrom:[gNewSense 3.0 _Parkes_ - Official i386 LIVE/INSTALL
>         Binary 20140205-19:57]/ parkes main
> 
>         # Line commented out by installer because it failed to verify:
>         deb http://archive.gnewsense.org/gnewsense-three/gnewsense
>         parkes-security main
>         # Line commented out by installer because it failed to verify:
>         deb-src http://archive.gnewsense.org/gnewsense-three/gnewsense
>         parkes-security main
> 
>         # parkes-updates, previously known as 'volatile'
>         # A network mirror was not selected during install.  The
>         following entries
>         # are provided as examples, but you should amend them as appropriate
>         # for your mirror of choice.
>         #
>         deb http://ftp.debian.org/debian/ parkes-updates main
>         deb-src http://ftp.debian.org/debian/ parkes-updates main
> 
>         deb http://backports.debian.org/debian-backports
>         squeeze-backports main
>         deb http://mozilla.debian.net/ squeeze-backports iceweasel-esr
>         deb http://mozilla.debian.net/ squeeze-backports icedove-esr
>         # deb http://debian.net/debian experimental main
>         # deb http://mozilla.debian.net/ experimental iceweasel-beta
> 
> 
> Então faço apt-get update e apt-get upgrade e ele me oferece
> 
>         164 pacotes atualizados, 0 pacotes novos instalados, 0 a serem
>         removidos e 46 não atualizados.
>         É preciso baixar 172 MB de arquivos.
>         Depois desta operação, 51,9 MB de espaço em disco serão liberados.
> 
> 
> Posso e devo atualizar sem medo?

com esse sources.list desse jeito, você provavemente vai ter muitos
problemas. Não se mistura repositórios de sistemas diferentes.

-- 
Antonio Terceiro <terceiro@debian.org>

Attachment: signature.asc
Description: Digital signature


Reply to: