站長資訊網
        最全最豐富的資訊網站

        CentOS如何升級Bash(修復破殼漏洞)

        下面由centos教程欄目給大家介紹CentOS 升級 Bash — 修復破殼漏洞 ,希望對需要的朋友有所幫助!

        CentOS如何升級Bash(修復破殼漏洞)

        因為很多公司都有自己的 yum 源,所以直接配置其他的 yum 源升級的話是不允許的,為了能方便的升級,并且安全的測試,先拿一臺測試機做測試。

        CentOS 的修復方案

        安裝 yum 插件 yum-downloadonly

        注: yum-downloadonly 插件的作用是實現只下載所需包而不直接安裝

        sudo yum -y install yum-downloadonly

        添加 CentOS 的官方源 CentOS-Base.repo

        CentOS 5 的官方源

        # CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-5

        CentOS 6 的官方源

        # CentOS-Base.repo # # The mirror system uses the connecting IP address of the client and the # update status of each mirror to pick mirrors that are updated to and # geographically close to the client. You should use this for CentOS updates # unless you are manually picking other mirrors. # # If the mirrorlist= does not work for you, as a fall back you can try the  # remarked out baseurl= line instead. # # [base] name=CentOS-$releasever - Base mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os #baseurl=http://mirror.centos.org/centos/$releasever/os/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #released updates  [updates] name=CentOS-$releasever - Updates mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates #baseurl=http://mirror.centos.org/centos/$releasever/updates/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that may be useful [extras] name=CentOS-$releasever - Extras mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras #baseurl=http://mirror.centos.org/centos/$releasever/extras/$basearch/ gpgcheck=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #additional packages that extend functionality of existing packages [centosplus] name=CentOS-$releasever - Plus mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus #baseurl=http://mirror.centos.org/centos/$releasever/centosplus/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6 #contrib - packages by Centos Users [contrib] name=CentOS-$releasever - Contrib mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib #baseurl=http://mirror.centos.org/centos/$releasever/contrib/$basearch/ gpgcheck=1 enabled=1 gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-6

        下載最新的 bash 包

        把最新版本的 bash 的 rpm 包下載到 /tmp 目錄

        sudo  yum -y install --downloadonly --downloaddir=/tmp/ bash

        下載后的包名分別如下:

        CentOS 5

        bash-3.2-33.el5_10.4.x86_64.rpm

        CentOS 6

        bash-4.1.2-15.el6_5.2.x86_64.rpm

        安裝最新的 bash 包

        CentOS 5

        sudo yum -y install bash-3.2-33.el5_10.4.x86_64.rpm

        CentOS 6

        sudo yum -y install bash-4.1.2-15.el6_5.2.x86_64.rpm

        驗證

        env X='() { (a)=>' sh -c "echo date"; cat echo 輸出如下:

        date Mon Sep 29 10:11:56 CST 2014

        env VAR='() { :;}; echo Bash is vulnerable!' bash -c "echo Bash Hello" 輸出如下:

        Bash Hello

        證明修復成功

        加入現有的 rpm 源

        最后一步就是把測試完成的包加入公司自己的源中,然后全網推送了。

        贊(0)
        分享到: 更多 (0)
        網站地圖   滬ICP備18035694號-2    滬公網安備31011702889846號
        主站蜘蛛池模板: .精品久久久麻豆国产精品| 精品精品国产欧美在线小说区| 国产成人AV无码精品| 91麻豆精品一二三区在线| 99riav国产精品| 午夜精品久久久久久99热| 无码精品人妻一区二区三区漫画 | 亚洲色精品88色婷婷七月丁香| 中文无码久久精品| 精品国产呦系列在线观看免费| 四虎影院国产精品| 久久精品99久久香蕉国产色戒| 91国内外精品自在线播放| 亚洲精品一级无码鲁丝片 | 精品一区二区三区四区在线| 国产欧美久久久精品| 国产精品乱码一区二区三区| 久久夜色精品国产www| 无码人妻精品一区二区三区在线| 国产精品美女网站在线观看| 国产精品你懂得| 精品人妻码一区二区三区| 87国产私拍福利精品视频| 国产三级精品三级在线专区1| 亚洲精品第一国产综合境外资源 | 国产精品污WWW在线观看| 精品久久777| 久久亚洲精品无码观看不卡| 亚洲综合一区二区国产精品| 亚洲精品无码专区2| 久久99精品久久久久久不卡| 亚洲精品免费在线观看| 国产精品影音先锋| 91视频国产精品| 久久精品国产亚洲Aⅴ香蕉| 成人精品一区二区三区| 亚洲精品性视频| 亚洲国产成人久久精品影视| 欧美一卡2卡3卡四卡海外精品| 免费精品精品国产欧美在线| 精品国产福利在线观看|