[Freeswitch-users] lua os.execute fails after Centos 7.3 update (21-Jun-2017)

Yehavi Bourvine yehavi.bourvine at gmail.com
Wed Jun 21 14:22:11 UTC 2017


Hi,

  I managed to find a bypass in the meantime; see FS-10410.
I have no idea what are the side effects of it, but at least I can work now.

BTW, it looks that reports about other software packages being broken by
the security patch start to publish...

        Regards, __Yehavi:

2017-06-21 16:37 GMT+03:00 Yehavi Bourvine <yehavi.bourvine at gmail.com>:

> It is already disabled. I've found a new thread on RedHat's site that
> indeed the new patch breaks various type of process creation syscalls (like
> exec, system(), etc.). I tried raising the stack size as they suggest, but
> it does not help.
>
>          Thanks, __Yehavi:
>
> 2017-06-21 14:59 GMT+03:00 Luis Daniel Lucio Quiroz <
> luis.daniel.lucio at gmail.com>:
>
>> Try turning off selinux
>>
>> Le 21 juin 2017 2:47 AM, "Yehavi Bourvine" <yehavi.bourvine at gmail.com> a
>> écrit :
>>
>>> Hello,
>>>
>>>   Due to the recent security issues I did an update to my centos  7.3
>>> system which runs Freeswitch 1.6.17/18 (two systems); The main packages
>>> updated were the kernel and Libc. Since then, os.execute stopped working
>>> inside lua called scripts (luarun api); they fail with error 32512 which
>>> means that the command is not available. However, before the upgrade it
>>> worked, and so works the command itself when I run it from bash.
>>>
>>> Any idea? Some permissions has been changed at the security update?
>>>
>>>           Thanks, __Yehavi:
>>>
>>> ____________________________________________________________
>>> _____________
>>> Professional FreeSWITCH Consulting Services:
>>> consulting at freeswitch.org
>>> http://www.freeswitchsolutions.com
>>>
>>> Official FreeSWITCH Sites
>>> http://www.freeswitch.org
>>> http://confluence.freeswitch.org
>>> http://www.cluecon.com
>>>
>>> FreeSWITCH-users mailing list
>>> FreeSWITCH-users at lists.freeswitch.org
>>> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>>> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>>> http://www.freeswitch.org
>>>
>>
>> _________________________________________________________________________
>> Professional FreeSWITCH Consulting Services:
>> consulting at freeswitch.org
>> http://www.freeswitchsolutions.com
>>
>> Official FreeSWITCH Sites
>> http://www.freeswitch.org
>> http://confluence.freeswitch.org
>> http://www.cluecon.com
>>
>> FreeSWITCH-users mailing list
>> FreeSWITCH-users at lists.freeswitch.org
>> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>> http://www.freeswitch.org
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20170621/92c5bc74/attachment.html>


More information about the FreeSWITCH-users mailing list