Solaris 11.2 and bash vulnerability fix only for paid support customers ?
Hi,
Am I correct in saying that with respect to Solaris 11.2 the recent fixes for the bash vulnerabilities (CVE-2014-7169, CVE-2014-6271, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE-2014-6278) are only available via SRU 2.8 (i.e. to paid support customers) ? This would mean that the current public release version of Oracle Solaris 11 contains a major security hole and with no "public" remedy.
Assuming this is the case, is the release version likely to be fixed anytime soon ?
Any clarification on this appreciated.
Thanks
Grant,