Shell shock - Bash still is not updated

I purchased my Mac earlier this year (2014.7) and it was originally installed with OS X 10.9
I have currently formatted my Mac 5 times since I have purchased it due to issues with Bash, Java, Safari, the App store.
I believe I was victim to Shell shock as my Bash responds to the first vulnerability (First Update dated Sept 26, 2014, Bash version 3.2.53)
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
with a vulnerable output.
this is a test
I have downloaded the BashUpdateMavericks.pkg which NIST points to and it comes up with an error. I have tried installing the parch on both Mavericks and Yosemite and neither result in a successful instalment.
Can anyone give any insight on what I should do to patch up bash?

Apple's article about the BASH issue is here About OS X bash Update 1.0 - Apple Support
While this vulnerability is generically described as the shellshock aka. BASH issue, there actually several permutations of it. Some fixes only addressed some of those variations. As you will see Apple's article says they address two listed vulnerabilities but actually (as I read it) includes three different fixes.
The following article https://shellshocker.net seems to list six variations plus the original issue including the two Apple list.
On that basis one could argue Apple's fix does not address all the possible variations. However based on Apple's fix the result "this is a test" indicates the patch is correctly installed. Based on the shellshocker test all seven out of seven variations are fixed by Apple if you have the Apple patch installed.
This is the result I get on Mavericks 10.9.5 with Apple's patch applied.
CVE-2014-6271 (original shellshock): not vulnerable
CVE-2014-6277 (segfault): not vulnerable
CVE-2014-6278 (Florian's patch): not vulnerable
CVE-2014-7169 (taviso bug): not vulnerable
CVE-2014-7186 (redir_stack bug): not vulnerable
CVE-2014-7187 (nested loops off by one): not vulnerable
CVE-2014-//// (exploit 3 on http://shellshocker.net/): not vulnerable
With an unpatched copy of Mavericks I get the first four as vulnerable and the last three as not vulnerable suggesting Apple indeed only had to add three fixes. (The last six issues are variations of the first one.)
CVE-2014-6271 (original shellshock): VULNERABLE
bash: line 17: 54477 Segmentation fault: 11  shellshocker="() { x() { _;}; x() { _;} <<a; }" bash -c date 2> /dev/null
CVE-2014-6277 (segfault): VULNERABLE
CVE-2014-6278 (Florian's patch): VULNERABLE
CVE-2014-7169 (taviso bug): VULNERABLE
CVE-2014-7186 (redir_stack bug): not vulnerable
CVE-2014-7187 (nested loops off by one): not vulnerable
CVE-2014-//// (exploit 3 on http://shellshocker.net/): not vulnerable

Similar Messages

  • TS1814 I have windows vista and this did not work for my ipod it still will not update PLEASE HELP!

    I have windows vista and this did not work for my ipod it still will not update PLEASE HELP!
    iTunes for Windows: iTunes cannot contact the iPhone, iPad, or iPod software update server

    Try this:
    Close your iTunes,
    Go to command Prompt -
    (Win 7/Vista) - START/ALL PROGRAMS/ACCESSORIES, right mouse click "Command Prompt", choose "Run as Administrator".
    (Win XP SP2 n above) - START/ALL PROGRAMS/ACCESSORIES/Command Prompt
    In the "Command Prompt" screen, type in
    netsh winsock reset
    Hit "ENTER" key
    Restart your computer.
    If you do get a prompt after restart windows to remap LSP, just click NO.
    Now launch your iTunes and see if it is working now.
    If you are still having these type of problems after trying the winsock reset, refer to this article to identify which software in your system is inserting LSP:
    iTunes 10.5 for Windows: May see performance issues and blank iTunes Store
    http://support.apple.com/kb/TS4123?viewlocale=en_US

  • I need to change my account name but even if I updated it in the Adobe website, Revel still does not update my name at all! ***Urgent***

    I need to change my account name but even if I updated it in the Adobe website, Revel still does not update my name at all! ***Urgent***

    Good morning,
    Glad your account is up and running!
    As a note, the Revel service is not going away any time in the near future. The apps that are no longer available as of Dec. 8 are Grouppix and VideoBite
    Glenyse

  • After trying recommended fixes, iPad apps still do not update

    I am having an issue where my iPad apps do not update. I go to the app store, select update all, and enter my password. The black lines appear under the appropriate apps, but stay black. New apps also do not download. My network connection appears to be fine. This happened another time a month or so ago and I had to completely reset my iPad to fix it. Since this is becoming common, I do not want to have to keep starting from scratch for the fix. I have looked at many recommendations online and have tried them. Here is what I have unsuccessfully tried:
    I signed out of the store on my iPad, restarted and signed back in.
    I reset the settings.
    I updated and synced my apps from iTunes on my computer.
    I updated to the latest version of iTunes.
    If someone could provide a permanent fix, I would appreciate it. I would prefer not to have to completely reset my iPad once a month.

    Try this:
    Restart the iPad by holding down on the Sleep button until the red slider appears and then slide to shut Off. To power up hold the Sleep button until the Apple logo appears and let go of the button.
    Reset the iPad by holding down on the Sleep and Home buttons at the same time (for about 10-15 seconds) until the Apple logo appears (ignore the red slider), then let go of the buttons.
    Do any of the app icons say Waiting. If so, tap on an app icon that says Waiting.
     Cheers, Tom

  • I have disabled all Kaspersky security, windows firewall and windows defender and Itunes still will not update my Ipod touch 4th gen to IOS 5, Helppppp!

    I can't get the IOS 5 to work for windows Vista.  I'm running kaspersky pure 2.0, windows firewall and windows defender.  I have turned them all off, I then attach my Ipod 4th gen and I get the "cannot connect to itunes update server".  I ran diagnostics in itunes and it tells me I dont have a internet connection.  I'm on the internet right now, and I DO have a internet connection, but it tells me Itunes says otherwise.  I'm able to send this message on the same pc with internet connection but keep running into this error.  I have now read discussiong boards through apple and disabled all my firewalls, still no luck.  I was able to update the lates version of itunes, and just waiting to get my ipod updated now, please help me.

    On the computer you should be able to go to the network properites. Go to the TCP part and unchec the line that says obtaind DNS automatically and check the one that says use the following. Add the 8.8.8.8 and Google other 8.8.4.4.
    For more info see:
    https://developers.google.com/speed/public-dns/

  • I still can not update my imac from 10.8.2 to 10.8.3 how can i uodate it?

    when i click on update box the processs stops at 2.4 mb and it gets paused which the process takes 249 mb to be complete but it dosen,t change and stays at 2.4 mb , i tried even from support website >http://support.apple.com/kb/dl1640, with that when i start the updating it goes very slowly  to 57 mb then all of the sudden goes backward to 0 . it seems something block the process and  it dosen,t work . i live in middleeast and the speed of internet is not as fast as north america , could the problem be because of quqlity of or speed of internet ????? iam very frustrated

    Navigate to: ~/libary/Preferences/com.apple.SoftwareUpdate.plist and drag the file to the desktop. Then restart the computer in Safe Mode and use Software Update to download 10.8.3 and then restart normally.
    If you don't know how to get to the plist file noted above then:
    Finder - Go (menu) - Go to folder and copy and paste  ~/libary/Preferences/com.apple.SoftwareUpdate.plist in and hit Enter.

  • Why still can not update thunderbolt update 1.2.1

    I had newly bought a Thunderbolt Ethernet Adapter for my late 2010 MacAir.
    However, when I try to install the Thunderbolt update 1.2.1 and it keep shows "This software is not support in this system".
    Can someone tell me why ? and How can I solve this issue and make my ethernet adapter runs !
    Millions of thanks !
    Regards
    Ray

    Would it be because a 2010 MBA doesn't have a Thunderbolt port?
    http://support.apple.com/kb/SP618

  • HT201412 i have reset my ipad...i still will not update apps,down load apps, or load any existing apps.  Its just saying loading

    i cant update apps  they r just sitting sayind waiting....cant down load apps, cant open apps    and i have already tried reseting

    Here are several things that you can try. These have all worked for other users in the past however YMMV. One of the first two might be the way to go.  BTW - by "resetting" - I assume that you are talking about the two button hold down and wait for the Apple logo reboot.
    1. Make sure that you do not have a stalled download in iTunes - a song or podcast .... if you have a download in there that did not finish, complete that one first. Only one thing can download at a time on the iPad so that could be what is causing the problem.
    2. If that doesn't work - sign out of your account, restart the iPad and then sign in again.
    Settings>Store>Apple ID. Tap your ID and sign out. Restart the iPad by holding down on the sleep button until the red slider appears and then slide to shut off. To power up hold the sleep button until the Apple logo appears and let go of the button.
    Go back to Settings>Store>Sign in and then try to update again. Tap one waiting icon only if necessary to start the download stream.
    3. You can also try deleting the waiting icons - tap and hold down on an icon until it wiggles - the tap the X on the icon to delete it. Then try to download again.

  • HT4972 i have tried to restore my ipad it still will not update the os more thn 5.1.1

    I am trying to upgrade my os. i have restored it bu it still saying that 5.5.1 is the latest update

    The original iPad can't be updated past 5.1.1.
    (101799)

  • HT201210 Done everything possible to make it work but still its not updating... Please help, i ruined my whole sunday afternoon to update my ipad2 from ios 4.3 to ios 6. But now its stuck PLEASE HELP

    I am trying to update my iPad 2 from iOS 4.3.2 to iOS 6. but its stuck after 'extracting the software' thing. Its showing error no 3194 PLEASEEEEE HELPPPPPPP

    You've followed the instructions for that error code on the page that you posted from :
    Error 1004, 1013, 1638, 3014, 3194: These errors may be the result of the connection to gs.apple.com being redirected or blocked. Follow these steps to resolve these errors:
    Install the latest version of iTunes.
    Check security software. Ensure that communication to gs.apple.com is allowed. Follow this article for assistance with security software. iTunes for Windows: Troubleshooting security software issues.
    Check the hosts file. The restore will fail if there is an active entry to redirect gs.apple.com. Follow iTunes: Advanced iTunes Store troubleshooting to edit the hosts file or revert to a default hosts file. See section "Blocked by configuration: (Mac OS X/Windows) > Rebuild network information".
    Try to restore from another known-good computer and network.
    If the errors persist on another computer, the device may need service.

  • Can't sync new contacts from Outlook to iphone 6.  Turned off all add-ns and still will not update.

    Did the suggestion on the Apple site for contacts.  When I do the sync I can see the new contact in my contact list then it goes away when the sync finishes.

    @ Laurent P.
    Some things to try.
    Reset Sync History. To do this on a Mac, open iSync in your Applications folder. Once open, click the iSync menu and choose Preferences. Small window opens with a Reset Sync History button. Does not delete any data, just don't expect your next sync to be super quick.
    Also, under the Info tab in iTunes, choose the Advanced option of replacing everything on the iPhone with what is on the computer. If it works, be sure to uncheck that setting. I think it is a one time check only thing, but be sure.
    Wait...
    I just noticed you said MobileMe...if you use MobileMe to sync your stuff, flip Contacts Off then back On. If that doesn't work, delete the MobileMe account on the iPhone and re-add it.
    Otherwise, try a hard reset (both buttons for about 10 sec. ignore slide to power off), and reset network settings.
    Also, does the Mac contacts show up in MobileMe? If they don't, go to System Preferences > MobileMe > Sync tab and check your settings. Perform a sync too. Under the Advanced button you can Reset Sync Data and choose to replace MobileMe stuff with stuff on your computer or vice versa.
    Message was edited by: TonyElTigre
    I am a former .Mac user. I have both @mac and @me. No issues here after 2.0.2.
    Message was edited by: TonyElTigre

  • Trying to update to 6 ran firefox for 36 hrs still has not updated

    i saw message need to update to firefox 6 said ok went to firefox connecter the blue line showed connecting to firefox so i left it running overnight and all next day and it never completed to update how long do i need to wait im running windows xp and wireless hi speed

    Try to install it from scratch download fresh installer from getfirefox.com and install

  • PSA still not updated to target!

    Hi All,
      I see some weird thing in PSA. I dont know why all PSA's since last June..still says not updated to TARGET which is still in RED request.
    Whereas I can see my PSA request with RED MARK...although my data is updated in TARGET..
    Anyone has an idea why??

    Hi,
    If load to data target is successful, then PSA load Status will be turned as green (tick mark) for column request updated. In some cases, if request is not updated to data target or any error in loading to data target. Then request updated column will be displayed with red exclamation mark.
    Please reconcile your data target against PSA level periodic loads.
    Thanks,
    Manikandan Dhanakoti
    Edited by: Manikandan D on Jan 17, 2012 10:44 AM

  • Apps want update, i have done the reset thing still not update.

    Apps want update, I have done the reset thing and still will not update. I have tried 1 at a time and all at a time. I've done random apps still nothing. Anyone have any ideas before I put the phone in a sket launch and shoot it?

    Contact itunes support

  • Can not update iPod Nano, brand new and error says there is not enough room

    I just purchased my son a 1 gig nano. After registering and setting up options for updates. I got a message saying that it could not update because there wasn't enough room. I was trying to download less than 100 songs and all of them have been downloaded from iTunes. I have already completed the "5R's" as suggested in the troubleshooting section and it still will not update. iTunes recognizes his iPod, all software has been updated, I've reset and restarted. Very frustrated and my 11 year old is very devestated. Could someone please help?
    Thank you
    3pigsmama
    Dell Inspirion 6000   Windows XP  

    There's not an actual limit number to the ammount of songs that any iPod can hold. It's all size dependant. You might have simply downloaded a lot of large songs. When you're in iTunes check at the bottom of the screen to see how many megs or gig they actually take up. And keep in mind a 1 gig iPod isn't actually 1 gig. There is always a bit of space used up by system files and whatnot.

Maybe you are looking for

  • Mac app store won't open in mavericks OSX

    I had a power outage and it seems that since then, my OSX Mavericks on my iMAC won't open so I can't update my OS to Yosemite.  Can anybody help??  I have tried running permissions check and repair and still no luck.  I even did the safe mode bit and

  • Printing to PDF adds printer margins

    I have an extremely frustrating problem. I have a large Word doc with a full bleed border. I need to convert it to PDF for printing, but when I try, I get "the footer/margins in Section X are outside the printable area of the page." If I hit "ok," th

  • How to include one layout into other layout in Oracle Site studio designer

    Hi all, I have created the Header as on layout(This is my project specific even if we can go for fragments) in oracle site studio designer. It is the same case for footer, Left Nav. All these are primary pages in different sections. Now I have create

  • Ios 8.0.2 airprint

    HI, still no way to print.... i can select my samsung clx but it does'nt print... Any answer? thnks

  • Testing OA extension in JDeveloper

    Hi, I have extended a VO and tested in JDev in design time and its working fine. So, design time its working fine. This i have done in Tutorial.jpr project. To run through the 'test_fwktutorial.jsp' I followed the steps as defined in OA Framework dev