Patch here, here, here ... everywhere, really
By Darren Pauli, 2 Oct 2014 VMware is plugging away at Shellshock holes in 37 virtual appliance products, but has so far shipped clean code for just a handful of appliances.The company released a fix for cloud analytics kit vCenter Log Insight and offered updates on four others.
The advisory said a variety of VMware appliances shipped with Shellshock-vulnerable Bash.
Products running on Linux, Android, OSX and iOS could inherit the underlying vulnerability of their OS, and VMWare urges customers to contact their operating system vendor for a patch.
ESX variant ESXi is unaffected as it uses the Ash shell, while Windows products including vCentre Server are also unaffected clear.
Full Article