Oracle Solaris System Administration (MOSC)

MOSC Banner

Solaris 11.2 and bash vulnerability fix only for paid support customers ?

edited Oct 8, 2014 9:31AM in Oracle Solaris System Administration (MOSC) 2 commentsAnswered

Hi,

Am I correct in saying that with respect to Solaris 11.2 the recent fixes for the bash vulnerabilities (CVE-2014-7169, CVE-2014-6271, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE-2014-6278) are only available via SRU 2.8 (i.e. to paid support customers) ? This would mean that the current public release version of Oracle Solaris 11 contains a major security hole and with no "public" remedy.

Assuming this is the case, is the release version likely to be fixed anytime soon ?

Any clarification on this appreciated.

Thanks

Grant,

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center