Menu
Apple patches Bash vulnerability in OS X

Apple patches Bash vulnerability in OS X

The vulnerability posed little risk to most users

Apple has released a patch for Shellshock, a serious software vulnerability disclosed last week, although the company had said it posed no risk to most users.

Shellshock is the nickname for a flaw in the GNU Bourne Again Shell, or Bash, which is a command-line shell processor used for sending commands to an operating system. It is prevalent in Unix and Linux systems.

The flaw in Bash, which has been present for two decades, could allow an attacker to take complete control of a computer if the software is remotely accessible. An attacker could append malicious commands into a CGI (Common Gateway Interface) request, which would then be processed by a server.

The concern over Bash rivaled that of "Heartbleed," a vulnerability found in OpenSSL, a widely used open-source code library used to encrypted data between a client and a server. Like OpenSSL, Bash is present in a variety of software programs.

While security experts rank the Bash flaw as severe, the risk is dependent on how it is wrapped into other software.

Apple's OS X operating system is derived from Unix. Soon after the flaw became public, Apple advised that only users who have configured advanced Unix services may be vulnerable to the Bash flaw.

Security vendor Intego said Bash would be exposed on OS X if remote login was turned on for all users, a generally unsafe setting anyway. Older OS X servers that run Apache or PHP scripting environments could also potentially allow access to Bash, it said.

Apple has published separate Web pages containing the patch for Mavericks, Mountain Lion and Lion.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags patchesApplesecurityExploits / vulnerabilities

Featured

Slideshows

Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Tech industry comes together as Lexel celebrates turning 30

Tech industry comes together as Lexel celebrates turning 30

Leading figures within the technology industry across New Zealand came together to celebrate 30 years of success for Lexel Systems, at a milestone birthday occasion at St Matthews in the City.​

Tech industry comes together as Lexel celebrates turning 30
HP re-imagines education through Auckland event launch

HP re-imagines education through Auckland event launch

HP New Zealand held an inaugural Evolve Education event at Aotea Centre in Auckland, welcoming over 70 principals, teachers and education experts to explore ways of shaping and enhancing learning using technology.

HP re-imagines education through Auckland event launch
Show Comments