# bash patch for SLES 9

**URL:** <https://forums.suse.com/t/bash-patch-for-sles-9/26132>\
**Category:** SLES Updates\
**Created:** [September 25, 2014, 6:27pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132 "2014-09-25T18:27:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rustyshields](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@rustyshields](https://forums.suse.com/u/rustyshields)\
**Post date:** [September 25, 2014, 6:27pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/1 "2014-09-25T18:27:24Z")

</div>

Any chance a patch will be made available to fix this bug for SLES 9?

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [September 25, 2014, 6:54pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/2 "2014-09-25T18:54:50Z")

</div>

On 25/09/2014 16:34, rustyshields wrote:  
[color=blue]

> Any chance a patch will be made available to fix this bug for SLES 9?[/color]

Since SLES9 is outside the scope of Long Term Service Pack Support  
(LTSS) I would be extremely surprised if a patch was released for any  
SLES9 release.

It’s certainly not listed @  
[http://support.novell.com/security/cve/CVE-2014-6271.html](http://support.novell.com/security/cve/CVE-2014-6271.html)

Time to upgrade to something more current.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![rustyshields](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@rustyshields](https://forums.suse.com/u/rustyshields)\
**Post date:** [September 25, 2014, 7:26pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/3 "2014-09-25T19:26:57Z")

</div>

Thanks Simon,

We’re certainly working towards upgrading/replacing, but I can’t say that’s going to happen anywhere near fast enough to be a satisfactory solution to this issue.

I see patches released as recently of June of this year for “SUSE Linux Enterprise Server 9 SP4 LTSS”, so that gives me some small hope.

---

<div class="post-metadata">

**Author:** ![blortyblorty](https://avatars.discourse-cdn.com/v4/letter/b/a87d85/32.png) [@blortyblorty](https://forums.suse.com/u/blortyblorty)\
**Post date:** [September 25, 2014, 9:51pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/4 "2014-09-25T21:51:18Z")

</div>

Any downside to installing from source on SLES 9 or earlier (unsupported) versions of SLES 10…?

`mkdir src
cd src
wget http://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz
#download all patches
for i in $(seq -f "%03g" 0 25); do wget http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-$i; done
tar zxvf bash-4.3.tar.gz 
cd bash-4.3
#apply all patches
for i in $(seq -f "%03g" 0 25);do patch -p0 < ../bash43-$i; done
#build and install
./configure && make && make install
cd .. 
cd ..
rm -r src`

---

<div class="post-metadata">

**Author:** ![rustyshields](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@rustyshields](https://forums.suse.com/u/rustyshields)\
**Post date:** [September 26, 2014, 2:46pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/5 "2014-09-26T14:46:52Z")

</div>

That’s what I’m planning to do at this point.

[QUOTE=blortyblorty;23833]Any downside to installing from source on SLES 9 or earlier (unsupported) versions of SLES 10…?

`mkdir src
cd src
wget http://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz
#download all patches
for i in $(seq -f "%03g" 0 25); do wget http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-$i; done
tar zxvf bash-4.3.tar.gz 
cd bash-4.3
#apply all patches
for i in $(seq -f "%03g" 0 25);do patch -p0 < ../bash43-$i; done
#build and install
./configure && make && make install
cd .. 
cd ..
rm -r src`[/QUOTE]

---

<div class="post-metadata">

**Author:** ![mikewillis](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@mikewillis](https://forums.suse.com/u/mikewillis)\
**Post date:** [September 26, 2014, 3:12pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/6 "2014-09-26T15:12:13Z")

</div>

> [@rustyshields;23854](#):
>
> That’s what I’m planning to do at this point.

If you’re going to build from source, might it be a good idea not to overwrite stuff all over the place by compiling with prefix of /usr then running ‘make install’? (as previously posted example which the forum software has cut out of the quote block does.)  
Maybe worth considering building with prefix of /usr/local or /opt, or even /usr/local/bash4 or /opt/bash4, then rename the bash binary provided as part of SLES 9 and replace with symlink to the new one. That way you have a quick easy way to revert to the bash that was provided as part of SLES 9 should that be desired for some reason.

---

<div class="post-metadata">

**Author:** ![rrysiew](https://avatars.discourse-cdn.com/v4/letter/r/8dc957/32.png) [@rrysiew](https://forums.suse.com/u/rrysiew)\
**Post date:** [September 26, 2014, 4:59pm UTC](https://forums.suse.com/t/bash-patch-for-sles-9/26132/7 "2014-09-26T16:59:19Z")

</div>

I did this on SLES 10 SP3 and it was successful in upgrading to bash version 4.3  
However, when I test if it is still vulnerable by running: env x=’() { :;}; echo vulnerable’ bash -c ‘echo hello’  
It says it is vulnerable.

I got that test from here: [http://askubuntu.com/questions/528101/what-is-the-cve-2014-6271-bash-vulnerability-and-how-do-i-fix-it](http://askubuntu.com/questions/528101/what-is-the-cve-2014-6271-bash-vulnerability-and-how-do-i-fix-it)

Any ideas what is wrong?

Thanks,  
Rob
