[BUG] Jolla bash shell is affected by the #shellshock bug [answered]
Any ETA for a fix? Pretty nasty vulnerability this is :)
We have moved to a new Sailfish OS Forum. Please start new discussions there.
Update 9 will contain fixes for:
I'd appreciate if people would stop finding critical issues in core components just when we're about to wrap up for releasing ;)
They're not done with fixing this issue ... http://seclists.org/oss-sec/2014/q3/734
max ( 2014-09-26 12:06:18 +0200 )editThanks for the report. We are working to include this fix in next release.
Please next time also send the report to security@jolla.com which is meant for this kind of issues.
I think it is fair to expect that people in Jolla would have organized vulnerability management professionally, and issue advisories to like https://lists.debian.org/debian-security-announce/ and all other seriousl distros. Security community has been all over this issue last 24 hours, please do not say you found out this issue 5 mins ago? I trust not, you just didn't have time to communicate this to the community, right?
Jiikoo ( 2014-09-25 10:59:45 +0200 )editJiikoo, unlike other projects like Debian Jolla to my knowledge does not have a complete public roadmap over upcoming features and fixes. Therefore many together tickets will get replays like this "where already aware and working on it for an upcoming release".
Louis ( 2014-09-25 11:08:34 +0200 )editThis thread is public, all members of Together.Jolla.Com can read this page.
Asked: 2014-09-25 10:03:18 +0200
Seen: 1,627 times
Last updated: Sep 25 '14
[Fixed in 1.0.3.8] Crash when linking contacts? [not relevant]
Time slider usage in video player of Gallery app causes the app to hang [duplicate]
QAudioOutput isn't integrated with system volume and libresource like QMediaPlayer
Bug: E-Mail synchronization does not work as configured [released]
Word prediction should be always turned off when entering passwords in Android apps [released]
Don't enforce focus to textfield [answered]
[Implemented in 1.0.3.8] Email: Honour Reply-To header [answered]
I would be great to have this fixed with the upcoming 1.0.9.x update :)
Louis ( 2014-09-25 10:10:08 +0200 )editAny instructions to recompile bash with basic *ux skills as an workaround would be helpful to fellow sailors NOT developing with SDK daily.
Just did it for my MacOs X, good instructions there: http://apple.stackexchange.com/questions/146849/how-do-i-recompile-bash-to-avoid-the-remote-exploit-cve-2014-6271/146851#146851
Jiikoo ( 2014-09-25 10:10:21 +0200 )editJiikoo: Are you sure recompiling bash on SailfishOS on your own is a good idea? It could mess up your system especially when next update will be released and some core apps are custom compiled outside the package manager.
Louis ( 2014-09-25 10:21:38 +0200 )editLouis: Well, doing it all the time in my *ux boxes. Let me first re-phrase: "Instructions to compile & package patched bash-package, which could be later replaced by official bash package during next OS update." I have to admit I'm not familiar to SailfishOS peculiarities, but I would assume bash is an atomic executable that could be patched temporarily with small risk of messing other apps. At least I'm more willing to take that risk instead of taking any security risk - but that is of course a matter of personal preference.
Jiikoo ( 2014-09-25 10:28:48 +0200 )editI read on IRC that this will be tentatively fixed with update 9 (from Aard)...
pat_o ( 2014-09-25 10:50:52 +0200 )edit