DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Are any Vigor Routers affected by the BASH bug?

More
26 Sep 2014 11:34 #81286 by siv
I just used the search feature on the support page and found this:

Security Advisory: Shellshock / Linux 'Bash' Vulnerability

In September 2014, news broke of a vulnerability in the 'Bash' command line interface (CLI), commonly referred to as a shell, which has been named 'Shellshock'. This vulnerability is also known by the identifications CVE-2014-6271 or VU#252743 and related CVE-2014-7169 for Redhat Linux.

The 'Bash' shell is used by many Internet servers and also hardware products which are based on Linux, including MacOS (Apple desktop computers and laptops). The bash CLI is widely used, and many vendors use common builds and code libraries, as well as the same OEMs so the vulnerability may affect many different vendor's products (different brands). You should check each of your hardware products (routers, servers, other Linux-embedded systems etc.) and patch where appropriate. Note that DrayOS, the operating system used for most DrayTek products is proprietary, not Linux based and using exclusively our own developed code, not shared by other vendors.

DrayTek Products
We can confirm that no DrayTek hardware products are affected by Shellshock or use the affected code, libraries or functions.

The above statement covers all DrayTek hardware products ('Vigor' series products), including all routers, wireless access points and switches. The above statement also covers/includes the public servers providing the following web sites: draytek.com, draytek.co.uk, draytel.org, seg.co.uk and includes all sub-domains of those web sites such as forum.draytek.co.uk or myvigor.draytek.com.

None of these aforementioned products or sites use the vulnerable code or libraries and are therefore considered 'safe' in this respect. It is not necesary to take any action on any of these products, services or accounts in respect of Shellshock.

Advice Regarding other Services / Products (non-DrayTek)
You should check equivalent statements/advisories from the providers of all of your other networking hardware vendors, servers, PCs, web service providers and ISPs and then follow the advice of each of them regarding any necessary precautions or updates. For more technical details of Shellshock, visit CERT UK (External site; outside the responsibility of DrayTek).

So it looks like we are OK!

The link to that page is here:

http://www.draytek.co.uk/support/guides/shellshock-security-exploit?highlight=WyJzaGVsbHNob2NrIiwiJ3NoZWxsc2hvY2snLiIsImV4cGxvaXQiLCJzaGVsbHNob2NrIGV4cGxvaXQiXQ==

Graham Sivill

Please Log in or Create an account to join the conversation.

More
26 Sep 2014 11:39 #81287 by booree
that's fantastic .. thank you so much Siv .. saved me a lots of hours .. if Only Draytek could post something in the General Announcements as a routine.

Please Log in or Create an account to join the conversation.

More
26 Sep 2014 11:55 #81288 by dsll
That's a great relief.

Thanks very much for your help :)

Please Log in or Create an account to join the conversation.

More
26 Sep 2014 14:09 #81290 by babis3g
thanks :!:

Please Log in or Create an account to join the conversation.

Moderators: Sami