4 ms·
Is patching this bug on any server a matter of running `sudo apt-get update` (or the equivalent of the linux flavor in question) - and then rebooting afterwards
by codeisawesome 11y ago
Is patching this bug on any server a matter of running `sudo apt-get update` (or the equivalent of the linux flavor in question) - and then rebooting afterwards?
EDIT:
From AWS (https://aws.amazon.com/security/security-bulletins/cve-2015-7547-advisory/ https://aws.amazon.com/security/security-bulletins/cve-2015-...):
"""
We have reviewed the issues described in CVE-2015-7547 and have determined that AWS Services are largely not affected. The only exception is customers using Amazon EC2 who’ve modified their configurations to use non-AWS DNS infrastructure should update their Linux environments immediately following directions provided by their Linux distribution. EC2 customers using the AWS DNS infrastructure are unaffected and don’t need to take any action.
"""
- deleted 11y ago[deleted]
- cbd1984 11y ago> Is patching this bug on any server a matter of running `sudo apt-get update` (or the equivalent of the linux flavor in question) - and then rebooting afterwards? That's how a well-configured server works by definition. How much do you want to bet your server's well-configured?
- INTPenis 11y agoYes, when I woke up the morning after the advisory all my servers were already patched. I only had to reboot them. Thanks to things like yum-cron and unattended-upgrades.
- tie_ 11y agoFirst, until you reboot your servers, they are not really patched. Second, you are happy about unattended core system upgrades to production machines? I don't think this is the right feeling to have :)
- jlgaddis 11y agoAs a general rule, I would agree with you (with regard to point two). However, you don't know the details of INTPenis' infrastructure so you can't know. Perhaps automated / unattended upgrades / reboots would totally hose your environment but that's not the case in every instance.
- INTPenis 11y agoDepends on the environment, but I can safely say that I allow security updates without reboot in most production environments and have yet to run into problems. Rough estimate I'd say it's 50/50 whether I patch manually or allow unattended patches.
- dakami 11y agoIf this bug ends up traversing caches, it'll affect Amazon just like everything else. That the bug is so resistant to clear-cut answers on cache traversal vulnerability is unique, practically unprecedented.
- 0x0 11y agoOf course, you should also run "sudo apt-get upgrade" after "update" :)