Fix ‘Shell Shock’ bash vulnerability in OS X 10.5

Discussion in 'PowerPC Macs' started by Hack5190, Feb 13, 2016.

  1. Hack5190 macrumors 6502a

    Hack5190

    Joined:
    Oct 21, 2015
    Location:
    Stuck on Earth in the USA
    #1
    Tonight I tested sh and bash on my Leopard install using the script from here (https://github.com/wreiske/shellshocker/blob/master/shellshock_test.sh).

    Both were vulnerable, after some searching I was able to use the information from this posting (http://www.macissues.com/2014/09/25...x-the-shell-shock-bash-vulnerability-in-os-x/) to patch and compile updated versions of sh and bash.

    If you wish to use the updated versions I compiled, they are available to download from here https://www.dropbox.com/s/h8ugiy5t53uwth1/shellshock.zip?dl=0

    For connivence the script to test for shell shock vulnerability is included in my download.
     
  2. Intell macrumors P6

    Intell

    Joined:
    Jan 24, 2010
    Location:
    Inside
    #2
  3. Hack5190, Feb 14, 2016
    Last edited: Feb 15, 2016

    Hack5190 thread starter macrumors 6502a

    Hack5190

    Joined:
    Oct 21, 2015
    Location:
    Stuck on Earth in the USA
    #3
    Thanks for the info and link, having only joined the PowerPC owners club (and this forum) in Nov of 2015 I missed your thread.

    Truth is the primary reason I did this was to test my compiler install and for something to do last night while others in the house watched the Republican comedy show (aka debate).
     
  4. Gamer9430 macrumors 68020

    Gamer9430

    Joined:
    Apr 22, 2014
    Location:
    Central New Jersey, USA
    #4
    Sorry if I'm a bit late to the party on this, but what exactly does is the vulnerability?
     
  5. throAU macrumors 601

    throAU

    Joined:
    Feb 13, 2012
    Location:
    Perth, Western Australia
    #5
    If you're running 10.5 shellshock is the least of your concerns.

    For example, there is a vulnerability in NSString (pretty sure un-patched in 10.5) which will basically potentially allow any application on your machine to be exploited.
     
  6. Hack5190, Feb 14, 2016
    Last edited: Feb 14, 2016

    Hack5190 thread starter macrumors 6502a

    Hack5190

    Joined:
    Oct 21, 2015
    Location:
    Stuck on Earth in the USA
    #6
  7. Cox Orange macrumors 68000

    Joined:
    Jan 1, 2010
    #7
    Here they say it will work under 10.4, too
    http://resale.headgap.com/bobsmactips.html (hit cmd+f and type "bash problems" to find the part I am referring to)
    Mind there they are linking to the version that ends with .27 while tenfourfox-blogspot has updated it to .30

    Is Intel's installer using vs. .30 ?
     
  8. Intell macrumors P6

    Intell

    Joined:
    Jan 24, 2010
    Location:
    Inside
    #8
    Yes, my installer does use version 4.3.30(5) of bash.
     

Share This Page