cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
564
Views
0
Helpful
3
Replies

Ghost Vulnerability patching confusion

Tim Hamblin
Level 1
Level 1

Hi all,

 

We are currently running ACS v5.4 and were looking to go to patch 7 initially to combat shellshock.

 

Then GHOST came along so we waited for Cisco's advisory on the best version to go to.

 

This has now come out and the advisory is less than helpful!!! - https://tools.cisco.com/bugsearch/bug/CSCus68826

 

On one habd it seems to say 5.4 is good and on the other that all versions are vulnerable!

 

Can anybody clarify what patch/version we need to negate the vulnerability please :)

 

Document is too confusing!!!

 

Tim

 

 

2 Accepted Solutions

Accepted Solutions

Kanwaljeet Singh
Cisco Employee
Cisco Employee

Hi Tim,

I have double checked and all 5.x versions are affected. The fixes are not available for 5.4 or 5.3 but 5.5 and 5.6. Kindly upgrade to get the fixes.

Regards,

Kanwal

Note: Please mark answers if they are helpful.

View solution in original post

mohanak
Cisco Employee
Cisco Employee

Install the latest patches 5.5 Patch 8 and 5.6 patch 3.

View solution in original post

3 Replies 3

Kanwaljeet Singh
Cisco Employee
Cisco Employee

Hi Tim,

I have double checked and all 5.x versions are affected. The fixes are not available for 5.4 or 5.3 but 5.5 and 5.6. Kindly upgrade to get the fixes.

Regards,

Kanwal

Note: Please mark answers if they are helpful.

mohanak
Cisco Employee
Cisco Employee

Install the latest patches 5.5 Patch 8 and 5.6 patch 3.

Tim Hamblin
Level 1
Level 1

Thanks all, will look to upgrade :)