Skip to main content

Shellshock bug in Bash affects Linux and Mac OS X, but the first fixes are already out (Updated)

hacking team adobe flash windows security exploit cyber
Update 9/26/14 6:04 p.m. ET by Konrad Krawczyk: According to the official Red hat security blog, additional patches that are designed to combat and rectify the problems associated with the Shellshock bug in Bash have been released.

On top of that, Red Hat says that “patches are available for most operating systems.”

Red Hat goes on to say that it does not know of any exploits which target Bash on systems that have the latest patches installed. As for why these flaws weren’t discovered faster, the blog post states that the holes in Bash were in a feature that was “obscure” and “rarely used.”

As for OS X based systems and the risks posed to them as a result of this threat, an Apple rep reportedly stated that the “vast majority of OS X users are not at risk to recently reported bash vulnerabilities.”

Original story

The hits just keep on coming for the cyber security world. The newest threat to land is called Shellshock, and it affects something called Bash.

Bash, which is short for “Bourne again shell,” is a piece software that controls Linux’s and OS X’s command prompt. The U.S. government says that the vulnerability in Bash affects “Unix-based operating systems such as Linux and Mac OS X.”

The United States Computer Emergency Readiness Team states that the flaw could “allow a remote attacker to execute arbitrary code on an affected system.”

Related: How to check if your servers and systems are affected by the Shellshock flaw in Bash

The National Vulnerability Database rates the severity of this problem at “10.0 HIGH.” On top of that, at least one cyber security expert says that it’s not difficult for a seasoned hacker to exploit the flaw in Bash.

“Using this vulnerability, attackers can potentially take over the operating system, access confidential information, make changes, et cetera,” Tod Beardsley of Rapid7, a cyber security firm, said to Reuters. “Anybody with systems using Bash needs to deploy the patch immediately.” 

The first patch that was released to address the flaw was found to have problems of its own, preventing it from fixing the issues that it was designed to rectify in the first place. That’s according to the official Red Hat Security Blog.

This is being followed up with a new patch that should right the wrongs caused by the first update. However, Red Hat still recommends that users apply the original, buggy patch, instead of waiting for the new patch to come out.

That’s because, as Red Hat’s latest security blog update states, the problems associated with the flawed patch are “less severe,” and that “patches for it are being worked on.

In the meantime, Apple has yet to issue any patches of its own that address the Shellshock bug.

 

Editors' Recommendations

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Latest MacOS update causing monitor and controller issues
The Mac Studio and Studio Display at Apple's Peek Performance event.

Mac owners updating to the latest version of Apple's operating system are experiencing problems with connectivity to select peripherals, including game controls, displays, and graphics cards housed inside eGPUs.

The problems stem from updates to the latest version of Apple's MacOS 12.3, with people turning to various blogs, forums, and Reddit to report these issues. Apple has not acknowledged or addressed these complaints, and it's unknown how widespread these problems are among MacOS 12.3 users.

Read more
The latest MacOS update is bricking some people’s Macs
Apple MacBook Pro front view showing display and keyboard..

Normally, we’d encourage you to always update to the latest version of your operating system. But some Mac users got more than they bargained for when they installed the latest MacOS Monterey 12.3 update -- it bricked their devices.

According to posts on Apple’s developer forums and on social media, the 12.3 update is causing all manner of issues, from simple error messages to infinite rebooting loops and completely bricked Macs. Attempting to upgrade from MacOS Monterey 12.2.1 or earlier appears to be causing the problems.

Read more
This MacOS Trojan stealthily lifts your data, says Microsoft
The screen of the 2021 MacBook Pro.

You might think that your Mac is invulnerable to viruses and other security threats, but you might want to think again. As part of its commitment to intelligence sharing and collaboration, Microsoft recently exposed the evolution of a MacOS Trojan that can stealthily lift your personal data.

First spotted in September 2020, Microsoft says this piece of malware, known as UpdateAgent,  has increasingly progressed to "sophisticated capabilities." Though it also indicated that the latest two versions are still more "refined," Microsoft does warn that the malware is again being developed, and more updates could come soon.

Read more