As promised, Apple on Monday issued OS X bash Update 1.0 for OS X Mavericks, Mountain Lion and Lion, targeting the recently discovered "Shellshock" security flaw originating in the bash UNIX shell.
Following revelations that Shellshock was in the wild, Apple last Friday said that, while most consumers would go unaffected, it was working to patch the problem. That fix was released today for OS X 10.9 Mavericks, OS X 10.8 Mountain Lion and OS X 10.7 Lion.
This update fixes a security flaw in the bash UNIX shell.
The bug, dubbed "Shellshock" by the computer security community, is theorized to be built in to every version of bash since the system's inception in 1989. A remote attack, nefarious users could potentially issue commands to an affected computer with the intent of gathering information modifying system files and more.
"With OS X, systems are safe by default and not exposed to remote exploits of bash unless users configure advanced UNIX services," an Apple spokesperson said last week, adding that the company is "working to quickly provide a software update for our advanced UNIX users."
Mac owners running Mavericks can download the 3.4MB patch through Apple Support website, as can users operating Mountain Lion and Lion. For Mountain Lion, the fix comes in at 34.3MB, while the Lion download clocks in at 3.5MB. Alternatively, the patch is available through Software Update.
19 Comments
I guess since Yosemite DP9 is tomorrow they’re ignoring us for now.
Cool. Not showing up for me yet. I had already installed the MacPorts version of bash, but it's good that Apple's version is being updated.
I guess Mountain Lion was extra broke. :D
For Tiger (don't ask) is it enough to do a command line shell change - to ksh?
[quote name="jpellino" url="/t/182567/apple-releases-bash-patch-to-plug-shellshock-security-flaw-in-os-x-mavericks-mountain-lion-lion#post_2609701"]For Tiger (don't ask) is it enough to do a command line shell change - to ksh?[/quote] http://tenfourfox.blogspot.com/2014/09/bashing-bash-one-more-time-updated.html Should be all you need to fix it. I still run Tiger on my Cube as a music server, and on my 12" PB (admittedly, I don't use that one much anymore).