Q: Has an OS update been released for the shellshock vulnerability?
I'm running OS X (10.7.5) and applied a software security update this morning (9/26). I'm wondering/hoping that this included a fix for the shellshock vulnerability. Does anyone know? BTW, I know Red Hat released a Bash update yesterday that we are applying to our servers. Now I just want to patch my home computer.
iMac (27-inch Mid 2011), Mac OS X (10.7.5)
Posted on Sep 26, 2014 7:11 AM
So to answer my own question, Apple has released a fix : About OS X bash Update 1.0 that addresses the Shellshock vulnerability (CVE-2014-6271 and CVE-2014-7169) for OS X. For my version on OS X (10.7 Lion) it can be downloaded from OS X bash Update 1.0 - OS X Lion & OS X Lion Server
Of course there are also patches available for 10.8 and 10.9.
As a rule, I choose to close all vulnerabilities on my systems regardless of whether I'm susceptible to the exploit or not. It's simply a good practice for anyone who is serious about security.
Posted on Oct 3, 2014 12:42 PM