Apple Patches Bash Vulnerability in OS X
Apple has released a patch for Shellshock software vulnerability disclosed last week, although the company had said it posed no risk to most users. Shellshock is the nickname for Bash, which is a command-line shell processor used for sending commands to an operating system.
The flaw in Bash could allow an attacker to take complete control of a computer if the software is remotely accessible. An attacker could append malicious commands into a CGI (Common Gateway Interface) request, which would then be processed by a server.
Apple's OS X operating system is derived from Unix. Soon after the flaw became public, Apple advised that only users who have configured advanced Unix services may be vulnerable to the Bash flaw.
Apple has released separate patched for Mavericks, Mountain Lion and Lion:
- OS X bash Update 1.0 - OS X Mavericks - http://support.apple.com/kb/DL1769
- OS X bash Update 1.0 - OS X Mountain Lion - http://support.apple.com/kb/DL1768
- OS X bash Update 1.0 - OS X Lion - http://support.apple.com/kb/DL1767