Hi Alan,

This has not been a low priority for Apple. You can and have been able to 
download the patch from Apple Support at:

<http://support.apple.com/kb/DL1769?viewlocale=en_US&locale=en_US>
------
Shellshock Vulnerability: What Mac OS X Users Need to Know
What exposes your Mac to Shellshock

There are two routes to exposing this vulnerability to a remote attack on a Mac:

Route 1

Go into System Preferences > Sharing and turn on Remote Login
In the same location, turn on All Users
Go into System Preferences > Users & Groups and make sure Guest Access is 
enabled                                                                         
                                                                                
                          Your system is now vulnerable. If you don’t enable 
guest access your system is still vulnerable if the attacker knows or is able 
to guess your username and password.                                         
But as this connection is secured, they can’t get that from packet sniffing. 
And enabling a guest shell on a box is probably not the most secure thing to do 
anyway.
Route 2

This route requires OS X Server, an old (Lion or earlier) version of OS X, or 
for the user to install Apache/PHP/some other scripting environment.

Enable Apache and have it running
Enable Apache to run scripts or execute extensions
Have one of those scripts or extensions vulnerable to malicious attacking 
(being able to inject something into the script that gets executed)
The attacker can then insert the variables into the script or extension that 
gets run under the Bash shell, then the injection gets into the Shellshock 
vulnerability, and voila—machine compromised. This one, however, requires 
exploiting two holes. First, in the script running on Apache, and then in turn 
using that compromised script to send something to the Bash shell.

What this means 

As you can see, these are both edge cases. And both routes probably require a 
level of technical expertise that the person configuring their account as such 
can patch the exploit fairly simply.

Also note that for route 1, enabling a Bash shell with Guest access for remote 
login most likely opens up your system to many other possible attacks. The 
difference Shellshock provides is access to root privileges, in other words 
full machine access to said Guest user.

The bigger issue is all the devices with embedded Unix, where telnet 
(unsecured) access is enabled, and no login is required. These typically are 
“The Internet of Things” (IoT) devices. Even if they require an administrator 
password other then “Admin” to get change settings, Shellshock may now give the 
attacker root to do whatever they want on the device.

Prior to Apple patching this hole this is what you could have done do to stay 
protected

A few simple steps to make sure you’re not exposed:

Don’t enable Guest Access AND at the same time enable All Users for Remote 
Login.
Don’t run a Web server on your personal machine.
Have a strong password on your Account.
Keep Gatekeeper turned “On.”
Only install or run signed Apps from trusted sources.

Cheers,
Ronni

17" MacBook Pro 2.3GHz Quad-Core i7 “Thunderbolt"
2.3GHz / 8GB / 750GB @ 7200rpm HD

OS X 10.9.5 Mavericks
Windows 7 Ultimate (under sufferance)

On 2 Oct 2014, at 2:04 pm, Alan Smith <[email protected]> wrote:

> Obviously a low priority with Apple (I hope they're working overtime on 
> fixing iOS 8).
> 
> The UNIX bash update is NOT available from Software Updates.  What is a 
> reasonable time to wait for this “recommended” update to filter down to 
> ordinary users?
> 
> Cheers
> Alan
> (iMacs with Mavericks 10.9.5)
> 
> 
> On 30 Sep 2014, at 10:57 pm, Daniel Kerr <[email protected]> wrote:
> 
>> For those worried about the UNIX bash "issues", you can download updates for 
>> your OS now,…
>> http://support.apple.com/downloads/
>> 
>> Just choose your OS and can download the update. (if it isn't showing in 
>> Software Update already)
>> 
>> More info here - 
>> http://www.macrumors.com/2014/09/29/apple-os-x-mavericks-bash-update/
>> 
>> Kind regards
>> Daniel
>> 
>> Sent from my iPhone 6
>> 
>> ---
>> Daniel Kerr
>> MacWizardry
>> 
>> Phone: 0414 795 960
>> Email: <daniel AT macwizardry.com.au>
>> Web:   <http://www.macwizardry.com.au>
>> 
>> 
>> **For everything Apple**
>> NOTE: Any information provided in this email may be my personal opinion and 
>> as such should be taken accordingly, and may not be the views of 
>> MacWizardry. Any information provided does not offer or warrant any form of 
>> warranty or accept liability. It would be appreciated that if any 
>> information in this email is to be disseminated, distributed or copied, that 
>> permission by the author be requested. 

-- The WA Macintosh User Group Mailing List --
Archives - <http://www.wamug.org.au/mailinglist/archives.shtml>
Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.shtml>
Settings & Unsubscribe - <http://lists.wamug.org.au/listinfo/wamug.org.au-wamug>