It's not a complete fix. This still returns 'not patched':
foo='() { echo not patched; }' bash -c foo foo='() { echo not patched; }' bash -c fooIf you're facing an attacker with arbitrary control of both name and value of environment variables, and shell scripts that don't sanitize, you've got worse problems IMO.
Still, some Linux distributions are applying this unofficial patch, to only parse function definitions in prefixed environment variables to mitigate the threats.
[0] http://www.openwall.com/lists/oss-security/2014/09/25/13