Page 1 of 1

Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 10:28 am
by cuttime
I'm gun shy lately, and I don't understand why Apple hasn't pushed this security update through the App Store.

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 11:13 am
by billf
I'm wondering about that too.

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 3:23 pm
by rnappi
I installed it and haven't had any problems. Here's what apple has to say about security issues:http://support.apple.com/kb/HT1222

rich

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 3:27 pm
by bayswater
I was told this update is not required unless you've set up your Mac to run "advanced unix functions", whatever those are.

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 6:18 pm
by rnappi
I won't say whether you should or shouldn't install the update, but here's a test you can run in Terminal to see if you're potentially vulnerable:http://www.intego.com/mac-security-blog ... wLgPWBM%3D

Mine came back vulnerable, so I installed the patch and haven't had any problems.

rich

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 7:03 pm
by bayswater
I bet that test simply checks whether the update has been applied. But it's quick and easy to do, so there is no reason not to apply the fix. The downside is you have to be at 10.9.5. Apple has not provided an update for earlier releases of 10.9.

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 7:32 pm
by rnappi
From the linked article:

"...if your Mac is “vulnerable,” all this means is that your default shell is Bash. The only way for infections to occur is by exposing this vulnerability on a Mac."

rich

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 8:03 pm
by cuttime
Thanks for chiming in. Could Apple have made this process any more opaque?

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 8:13 pm
by bayswater
I expect they kept it low key because the vulnerability apparently there when you run web services off your Mac. You'd have to assume that's a pretty small proportion of their base.

Re: Anyone try the OSX Bash Update?

Posted: Wed Oct 01, 2014 10:54 pm
by James Steele
Yeah... I read what has to happen for the vulnerability to exploited and not many machines would be at risk. Still I just installed it on the Mac I'm on now (MacPro 1,1 running Lion) and it was painless and surprisingly did not require a reboot, which I didn't expect. I'll probably do it on all my Macs just for the heck of it.

Re: Anyone try the OSX Bash Update?

Posted: Thu Oct 02, 2014 12:11 pm
by billf
Here are the updater links for each OSX version:

OS X bash Update 1.0 may be obtained from the following at Apple:

http://support.apple.com/kb/DL1767 – OS X Lion
http://support.apple.com/kb/DL1768 – OS X Mountain Lion
http://support.apple.com/kb/DL1769 – OS X Mavericks