Page 1 of 1

Security Questions: ShellShock Bash and Heartbleed

Posted: Thu Sep 25, 2014 7:17 pm
by andrew
Does OPI contain either the ShellShock Bash vulnerability (see: http://securitywatch.pcmag.com/internet ... -computers) or the Heartbleed bug (see: http://heartbleed.com/)?

Thanks,
Andrew

P.S. I am eagerly looking forward to receiving my OPI soon!

Posted: Thu Sep 25, 2014 7:39 pm
by tor
Hi Andrew,

OPI does unfortunately indeed currently have a Bash version that is vulnerable for ShellShock.

The upgrade is in the pipeline and will be distributed shortly. I will update this topic when we have released the bash upgrade.

Regarding Heartbleed, this should be no issue since this is patched on Ubuntu since quite some time.

/Tor

Posted: Mon Sep 29, 2014 6:33 am
by tor
Just a follow up here.

We just pulled the Ubuntu updates on bash into our stable repositories. This means that all OPIs that have updates enabled should get this update shortly (~24h)

/Tor