CVE-2014-6271 ShellShock Bash Exploit

There’s a lot of miscommunication and misunderstanding here.

First off, yes, I am talking about the “Schmooze” Distro. Also, of note. Both @jfinstrom and I work for Schmooze. Originally many of you blindly posted multiple topics on/about this without taking the time to look at our banner and follow through to this thread. As of now I have merged all of your posts here for consolidation and locked the other threads (so don’t be offended if you find your thread locked)

At 3pm PST I checked both a 5.211.x distro and a 6.12.x distro. Both have the updated version of bash in the repo.

[root@localhost ~]# cat /etc/schmooze/pbx-version
5.211.65-17
[root@localhost ~]# yum list bash
Installed Packages
bash.i686                                4.1.2-15.el6_4                                   @updates
Available Packages
bash.i686                                4.1.2-15.el6_5.1                                 updates

I just checked again and both have this version. If you are on anything less than 5.211.x I recommend you take the following steps to upgrade your distro.

http://wiki.freepbx.org/display/FD/Updating+FreePBX+Official+Distro

For the 1.8 track (which is not able to go any higher than 1.8) I am not sure at this time.