U.S. government warns of Bash flaw affecting Apple’s OS X, other Unix-based systems

“The U.S. government has joined an array of researchers warning of a security flaw that could allow hackers to access devices ranging from computers to video cameras and steal data,” Tim Culpan reports for Bloomberg. “A vulnerability in some Unix-based systems, such as Linux and Mac OS X, ‘may allow a remote attacker to execute arbitrary code on an affected system,’ the U.S. Department of Homeland Security’s Computer Emergency Readiness Team said in a statement on its website. Systems administrators can fix the flaw with a patch, it said.”

“The vulnerability affects Bourne again shell, or Bash, one of the most widely installed pieces of software on any Linux system, software maker Red Hat Inc. said in a statement on its security blog. The vulnerability, dubbed Shell Shock, could let hackers insert extra code into a computer leading to data theft or the crashing of networks,” Culpan reports. “‘Today’s bash bug is as big a deal as Heartbleed,’ Robert Graham of Errata said in an earlier blog post yesterday, noting that Internet-of-things devices such as video cameras are also vulnerable. ‘The bug interacts with other software in unexpected ways.'”

Culpan reports, “Carolyn Wu, a Beijing-based spokeswoman for Apple, didn’t immediately return phone calls and an e-mail today. Apple’s Trudy Muller, based in Cupertino, California, didn’t respond to an e-mail after normal business hours.”

Read more in the full article here.

MacDailyNews Take: The hits just keep on comin’!


  1. CORRECTION: The vulnerability in BASH is an issue affecting UNIX and Linux. Apple OS-X is built on top of a UNIX kernel. This is something the media simply does not understand. Instead, the media prefers to infer that this is Apple’s fault, when it is a vulnerability in something that predates OS-X.

    Details, details. They’re so inconvenient when you have an agenda.

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.