[Version]
Qfix 1.0.2
[Description]
This Qfix fixed the GNU Bash Environment Variable Command Injection Vulnerability (CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-6278, CVE-2014-7186, and CVE-2014-7187)
It includes all of the fixes as of QTS 4.1.1 Build 1003. It is not necessary to install this Qfix patch if you have updated your NAS to QTS 4.1.1 Build1003.
[Applicable firmware]
QTS 3.8.3, QTS 3.8.4, QTS 4.0.7, and QTS 4.1.0.
It is recommended that users upgrade to the above firmware and then apply the Qfix.
[Qfix 1.0.1 vs. 1.0.2]
The difference between Qfix 1.0.1 and 1.0.2 on Bash issue is:
The Qfix 1.0.1 includes the update from Red Hat for the CVE-2014-6277 & 6278.
The Qfix 1.0.2 includes the update from official GNU Bash patch update for the CVE-2014-6277 & 6278.
[Applicable NAS]
All models except for TS-109, 209, and 409.
For TS-109/209/409/409U, please get the new firmware from this post:
http://forum.qnap.com/viewtopic.php?f=144&t=98706
[How to install Qfix]
The Qfix can be installed in the following steps:
Download “Qfix for Bash security patch" v1.0.2 from the QNAP website (http://www.qnap.com/download)
Upzip the downloaded file to have a .qfix file
Go to “QTS > Control Panel > System Settings > Firmware Update > Firmware Update” to apply the Qfix.
[Download link]
http://download.qnap.com/Storage/Qfix/Q ... 86_ARM.zip
[Security update] Qfix 1.0.2 for Bash vulnerability
Welcome note and must-know for QNAP Forum members.
- QNAPJason
- QNAP Staff
- Posts: 5398
- Joined: Thu May 21, 2009 2:14 pm
- Location: Taipei
Jump to
- QNAP General
- ↳ Announcements
- ↳ Features Wanted
- ↳ Users' Corner
- ↳ Official Apps
- ↳ Prestashop
- ↳ Webalizer
- ↳ Virtualization Station
- ↳ Notes Station
- ↳ SocialLink Station
- ↳ McAfee Antivirus
- ↳ IT Management Station
- ↳ Container Station
- ↳ Qsirch & Qfiling
- ↳ Community Apps
- ↳ Apps Wanted
- ↳ Partner Apps
- ↳ BitTorrent Sync
- ↳ EZPhone
- ↳ Plex Media Server
- ↳ Ragic
- ↳ Tonido
- Getting Started
- ↳ Frequently Asked Questions
- ↳ Presales
- ↳ Turbo Station Installation & Setup
- General
- ↳ Hardware & Software Compatibility
- ↳ HDD Spin Down (HDD Standby)
- ↳ Seagate Drive Discussion
- ↳ Western Digital Drive Discussion
- ↳ File Sharing
- ↳ Mac OS
- ↳ Linux & Unix (NFS)
- ↳ Windows
- ↳ Backup & Restore
- ↳ Symform
- ↳ Microsoft Azure
- ↳ OpenStack Swift
- ↳ Amazon Glacier
- ↳ Amazon S3
- ↳ WebDAV-based Backup
- ↳ Google Cloud Storage
- ↳ Object Storage Server
- ↳ ElephantDrive
- ↳ Xopero
- ↳ System & Disk Volume Management
- ↳ Web Server & Applications (Apache + PHP + MySQL / SQLite)
- ↳ Download Station and QGet
- ↳ myQNAPcloud service
- ↳ Surveillance Solution
- ↳ Miscellaneous
- ↳ QIoT
- ↳ QuAI
- ↳ QVR Face
- Business
- ↳ Windows Domain & Active Directory
- ↳ iSCSI – Target & Virtual Disk
- ↳ Remote Replication/ Disaster Recovery
- ↳ Server Virtualization & Clustering
- ↳ NAS Management
- ↳ QES Operating System (QNAP Enterprise Storage OS)
- Multimedia
- ↳ Photo Station, Music Station, Video Station
- ↳ Media Streaming
- ↳ Mobile Devices