Skip to main content

Shellshock bug in Bash affects Linux and Mac OS X, but the first fixes are already out (Updated)

hacking team adobe flash windows security exploit cyber
Image used with permission by copyright holder
Update 9/26/14 6:04 p.m. ET by Konrad Krawczyk: According to the official Red hat security blog, additional patches that are designed to combat and rectify the problems associated with the Shellshock bug in Bash have been released.

On top of that, Red Hat says that “patches are available for most operating systems.”

Red Hat goes on to say that it does not know of any exploits which target Bash on systems that have the latest patches installed. As for why these flaws weren’t discovered faster, the blog post states that the holes in Bash were in a feature that was “obscure” and “rarely used.”

As for OS X based systems and the risks posed to them as a result of this threat, an Apple rep reportedly stated that the “vast majority of OS X users are not at risk to recently reported bash vulnerabilities.”

Original story

The hits just keep on coming for the cyber security world. The newest threat to land is called Shellshock, and it affects something called Bash.

Bash, which is short for “Bourne again shell,” is a piece software that controls Linux’s and OS X’s command prompt. The U.S. government says that the vulnerability in Bash affects “Unix-based operating systems such as Linux and Mac OS X.”

The United States Computer Emergency Readiness Team states that the flaw could “allow a remote attacker to execute arbitrary code on an affected system.”

Related: How to check if your servers and systems are affected by the Shellshock flaw in Bash

The National Vulnerability Database rates the severity of this problem at “10.0 HIGH.” On top of that, at least one cyber security expert says that it’s not difficult for a seasoned hacker to exploit the flaw in Bash.

“Using this vulnerability, attackers can potentially take over the operating system, access confidential information, make changes, et cetera,” Tod Beardsley of Rapid7, a cyber security firm, said to Reuters. “Anybody with systems using Bash needs to deploy the patch immediately.” 

The first patch that was released to address the flaw was found to have problems of its own, preventing it from fixing the issues that it was designed to rectify in the first place. That’s according to the official Red Hat Security Blog.

This is being followed up with a new patch that should right the wrongs caused by the first update. However, Red Hat still recommends that users apply the original, buggy patch, instead of waiting for the new patch to come out.

That’s because, as Red Hat’s latest security blog update states, the problems associated with the flawed patch are “less severe,” and that “patches for it are being worked on.

In the meantime, Apple has yet to issue any patches of its own that address the Shellshock bug.

 

Editors' Recommendations

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
DuckDuckGo’s beta browser for MacOS puts privacy first
The DuckDuckGo Web Browser on MacOS

DuckDuckGo is entering the browser space on MacOS and, soon, Windows.

Just announced is the beta launch of a privacy-first web browser on MacOS, based on the same rendering engine as Safari, but with additional blockers and performance improvements.

Read more
The latest Mac Monterey update fixes some nasty bugs
The 2021 MacBook Pro with the lid open on a white table.

Apple's latest MacOS Monterey 12.3.1 update addresses the Bluetooth and display issues that have been plaguing Mac owners for several weeks.

Eligible Mac users can access and download the MacOS Monterey‌‌‌ 12.3‌‌.1 update through the Software Update section of System Preferences.

Read more
Latest MacOS update causing monitor and controller issues
The Mac Studio and Studio Display at Apple's Peek Performance event.

Mac owners updating to the latest version of Apple's operating system are experiencing problems with connectivity to select peripherals, including game controls, displays, and graphics cards housed inside eGPUs.

The problems stem from updates to the latest version of Apple's MacOS 12.3, with people turning to various blogs, forums, and Reddit to report these issues. Apple has not acknowledged or addressed these complaints, and it's unknown how widespread these problems are among MacOS 12.3 users.

Read more