Advertisement

Apple releases OS X bash Update 1.0



If you've been worried about the recent discovery of a security flaw called Shellshock in the bash UNIX shell, you can rest easier. Apple released OS X bash Update 1.0 to fix the issue, which made it possible for a remote attacker to execute arbitrary shell commands.

According to the release notes for the update, "an issue existed in Bash's parsing of environment variables. This issue was addressed through improved environment variable parsing by better detecting the end of the function statement."

The update incorporated a suggested change that resets the parser state, and also added a new namespace for exported functions. Versions of the patch are not only available for OS X Mavericks (see link in first paragraph), but also for OS X Lion, OS X Mountain Lion, and OS X Lion Server.

TUAW also posted instructions on patching OS X for the bash/Shellshock vulnerability last week.