Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. Web
  5. Legacy Archives

Shellshock bug in Bash affects Linux and Mac OS X, but the first fixes are already out (Updated)

Add as a preferred source on Google

Update 9/26/14 6:04 p.m. ET by Konrad Krawczyk: According to the official Red hat security blog, additional patches that are designed to combat and rectify the problems associated with the Shellshock bug in Bash have been released.

On top of that, Red Hat says that “patches are available for most operating systems.”

Recommended Videos

Red Hat goes on to say that it does not know of any exploits which target Bash on systems that have the latest patches installed. As for why these flaws weren’t discovered faster, the blog post states that the holes in Bash were in a feature that was “obscure” and “rarely used.”

As for OS X based systems and the risks posed to them as a result of this threat, an Apple rep reportedly stated that the “vast majority of OS X users are not at risk to recently reported bash vulnerabilities.”

Original story

The hits just keep on coming for the cyber security world. The newest threat to land is called Shellshock, and it affects something called Bash.

Bash, which is short for “Bourne again shell,” is a piece software that controls Linux’s and OS X’s command prompt. The U.S. government says that the vulnerability in Bash affects “Unix-based operating systems such as Linux and Mac OS X.”

The United States Computer Emergency Readiness Team states that the flaw could “allow a remote attacker to execute arbitrary code on an affected system.”

Related: How to check if your servers and systems are affected by the Shellshock flaw in Bash

The National Vulnerability Database rates the severity of this problem at “10.0 HIGH.” On top of that, at least one cyber security expert says that it’s not difficult for a seasoned hacker to exploit the flaw in Bash.

“Using this vulnerability, attackers can potentially take over the operating system, access confidential information, make changes, et cetera,” Tod Beardsley of Rapid7, a cyber security firm, said to Reuters. “Anybody with systems using Bash needs to deploy the patch immediately.” 

The first patch that was released to address the flaw was found to have problems of its own, preventing it from fixing the issues that it was designed to rectify in the first place. That’s according to the official Red Hat Security Blog.

This is being followed up with a new patch that should right the wrongs caused by the first update. However, Red Hat still recommends that users apply the original, buggy patch, instead of waiting for the new patch to come out.

That’s because, as Red Hat’s latest security blog update states, the problems associated with the flawed patch are “less severe,” and that “patches for it are being worked on.

In the meantime, Apple has yet to issue any patches of its own that address the Shellshock bug.

 

Konrad Krawczyk
Former Computing Editor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Claude is getting ambitious with watermarking, and I can smell the problems from a mile away
Claude’s text watermark could flag AI involvement even when it only helped with translation or editing
Claude website open on laptop

Anthropic wants to make AI-generated text easier to identify, and on paper, I have very little reason to complain. The company is experimenting with an invisible watermark that can be baked directly into text generated by Claude.

It sounds like a sensible idea. AI-generated text is everywhere, and knowing where something came from could certainly help. Moreover, Anthropic isn't simply hiding a marker somewhere inside a document. Its approach changes how Claude selects words to create a statistical pattern that can later be detected.

Read more
I switched from Windows to Mac after 25 years, and it’s the trackpad that converted me.
Well, that rhymes.
Computer, Electronics, Laptop

I’ve been using Windows laptops for almost 25 years. In that time, I never once seriously thought of buying a MacBook. In fact, I can honestly say I had never used one at all until I bought my MacBook Air M5 six months ago. Never borrowed one for a weekend, spent an afternoon at an Apple Store, or even played with one at a friend's house. Macs, to me, were just expensive computers for those who edited videos, made logos, or liked drinking expensive coffee.

My change came completely by accident.

Read more
Apple’s latest refurb drop brings cheaper MacBooks, iPhone 16 Plus, and Apple Watches
More M5 MacBook Air and Pro models are now available through Apple’s refurbished store
Computer, Electronics, Laptop

Apple has added several new MacBook Air and MacBook Pro configurations to its Certified Refurbished Store, alongside more iPhone 16 Plus models and Apple Watches.

The MacBook Air additions arrive at a particularly useful time. New M5 MacBook Air models are currently running in short supply across Apple’s retail network, with some configurations facing delivery estimates stretching into late August or September. Apple also raised MacBook Air prices in June, so students shopping before the new school year are being asked to spend more while potentially waiting longer to get one.

Read more