Neowin just published on this. This one’s worse than “Heartbleed”. Even if you aren’t running the above OSs, hackers can take control of any device running on operating systems that make use of Bash for command line operations. Also, some networking equipment such as routers and switches running on Linux variants also make use of Bash.
“The severity of the bug has been rated 10 out of 10 by Cybersecurity agency, Rapid7, due to its high risk and low complexity combination…The main differentiating factor between Heartbleed and Shellshock is that the latter allows hackers to take complete control of the target device while Heartbleed allowed hackers to steal the data that was transmitted.
The currently released patches make the vulnerability more difficult to exploit, but does not completely remediate the problem. In addition, Apple has yet to release an update, meaning that all Mac OS X machines are still vulnerable. Users should keep an eye on security updates and install as and when they are available. A list of fixes is available at US-CERT's website.” – Neowin
Source:
1. http://www.neowin.net/news/shellshock-bug-affecting-linux-unix-and-os-x-discovered
2. https://www.us-cert.gov/ncas/current-activity/2014/09/24/Bourne-Again-Shell-Bash-Remote-Code-Execution-Vulnerability