Jump to content

Bashing bash


RobertX
 Share

5 posts in this topic

Recommended Posts

...hi, this has been bugging me... :rolleyes: ....it seems like an exploit that could really do harm...therefore I'm posting this as a public service to all concerned...take it or leave it...it is what it is...both my boxes were vulnerable, and I'm assuming so are most if not all of yours...so until apple gets the fix...here is a link to a manual update of bash in Terminal...   tenfourfox.blogspot.com/2014/09/bashing-bash-one-more-time-updated.html  (just copy and paste into your address bar...my mistake)   :smoke:

Link to comment
Share on other sites

...well, I installed the fix from apple(installed over my manually updated bash)...it appears to address all exploits reported(public and private) that I'm aware of :whistle:

 

after fix applied, from terminal:

                                                   /bashcheck-master/bashcheck
Not vulnerable to CVE-2014-6271 (original shellshock)
Not vulnerable to CVE-2014-7169 (taviso bug)
Not vulnerable to CVE-2014-7186 (redir_stack bug)
Test for CVE-2014-7187 not reliable without address sanitizer
Variable function parser inactive, likely safe from unknown parser bugs

                                                                                                                                :smoke:

Link to comment
Share on other sites

 Share

×
×
  • Create New...