Shellshock
With the newest high profile vulnerability hitting the news wires, I imagine everyone is checking their servers.
Before we start hitting our machines though, any reason we should hold off on patching Bash? Obviously we will test on our non-prod servers first, but does Oracle specify a version or certify specific versions of Bash?