站長資訊網(wǎng)
        最全最豐富的資訊網(wǎng)站

        CentOS如何升級(jí)Bash(修復(fù)破殼漏洞)

        下面由centos教程欄目給大家介紹CentOS 升級(jí) Bash — 修復(fù)破殼漏洞 ,希望對(duì)需要的朋友有所幫助!

        CentOS如何升級(jí)Bash(修復(fù)破殼漏洞)

        因?yàn)楹芏喙径加凶约旱?yum 源,所以直接配置其他的 yum 源升級(jí)的話是不允許的,為了能方便的升級(jí),并且安全的測(cè)試,先拿一臺(tái)測(cè)試機(jī)做測(cè)試。

        CentOS 的修復(fù)方案

        安裝 yum 插件 yum-downloadonly

        注: yum-downloadonly 插件的作用是實(shí)現(xiàn)只下載所需包而不直接安裝

        sudo yum -y install yum-downloadonly

        添加 CentOS 的官方源 CentOS-Base.repo

        CentOS 5 的官方源

        # CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5

        CentOS 6 的官方源

        # CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6

        下載最新的 bash 包

        把最新版本的 bash 的 rpm 包下載到 /tmp 目錄

        sudo  yum -y install --downloadonly --downloaddir=/tmp/ bash

        下載后的包名分別如下:

        CentOS 5

        bash-3.2-33.el5_10.4.x86_64.rpm

        CentOS 6

        bash-4.1.2-15.el6_5.2.x86_64.rpm

        安裝最新的 bash 包

        CentOS 5

        sudo yum -y install bash-3.2-33.el5_10.4.x86_64.rpm

        CentOS 6

        sudo yum -y install bash-4.1.2-15.el6_5.2.x86_64.rpm

        驗(yàn)證

        env X='() { (a)=>' sh -c "echo date"; cat echo 輸出如下:

        date Mon Sep 29 10:11:56 CST 2014

        env VAR='() { :;}; echo Bash is vulnerable!' bash -c "echo Bash Hello" 輸出如下:

        Bash Hello

        證明修復(fù)成功

        加入現(xiàn)有的 rpm 源

        最后一步就是把測(cè)試完成的包加入公司自己的源中,然后全網(wǎng)推送了。

        贊(0)
        分享到: 更多 (0)
        網(wǎng)站地圖   滬ICP備18035694號(hào)-2    滬公網(wǎng)安備31011702889846號(hào)
        主站蜘蛛池模板: 午夜福利麻豆国产精品| 日本欧美国产精品第一页久久 | 国内少妇偷人精品视频免费| 国产精品自在线拍国产电影| 精品国产福利一区二区| 欧美ppypp精品一区二区| 911亚洲精品国内自产| 精品国产一区AV天美传媒 | 一区二区三区日韩精品| 亚洲国产成人一区二区精品区| 狠狠精品久久久无码中文字幕 | 久久精品国产精品青草app| 亚洲精品亚洲人成在线观看| 精品欧美一区二区三区久久久| 国产原创精品视频| 久久亚洲私人国产精品vA | 国产精品久久久久久久久免费 | 国产人妖乱国产精品人妖| 自拍偷自拍亚洲精品被多人伦好爽| 国内精品久久久久久久亚洲| 久久se精品一区精品二区| 国产精品污WWW在线观看| 人妻精品久久无码区| 中文字幕乱码中文乱码51精品| 久久久久亚洲精品无码网址| 国产亚洲精品看片在线观看| 99精品在线免费| 青青草国产精品| 久久99国产精品久久| 麻豆精品成人免费国产片| 久久精品国产91久久综合麻豆自制 | 精品国精品国产| 99精品久久精品一区二区| 国产精品无码专区| 国产欧美精品一区二区三区| 久久精品亚洲中文字幕无码麻豆| 亚洲av午夜福利精品一区| 亚洲精品国产品国语在线| 自拍偷自拍亚洲精品情侣| 香蕉久久夜色精品升级完成| 亚洲国产第一站精品蜜芽|