The BBC are inaccurate as usual: It is only a problem if you are passing unsanitised user input through Bash. Apache only does this for piped logs in 2.2 and below and it does not "include" bas, just uses it.
Other than that: Bash CGI, weak configurations of SSH together with a malicious user...
Debian and RH have patched, UBuntu is not vulnerable because it uses dash for scripts.