CVE-2014-6271

Published Sep 24, 2014

Last updated 4 months ago

Overview

Description
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Source
security@debian.org
NVD status
Deferred
Products
bash, eos, linux, qts, mageia, gluster_storage_server_for_on-premise, virtualization, enterprise_linux, enterprise_linux_desktop, enterprise_linux_eus, enterprise_linux_for_ibm_z_systems, enterprise_linux_for_power_big_endian, enterprise_linux_for_power_big_endian_eus, enterprise_linux_for_scientific_computing, enterprise_linux_server, enterprise_linux_server_aus, enterprise_linux_server_from_rhui, enterprise_linux_server_tus, enterprise_linux_workstation, studio_onsite, opensuse, linux_enterprise_desktop, linux_enterprise_server, linux_enterprise_software_development_kit, debian_linux, infosphere_guardium_database_activity_monitoring, pureapplication_system, qradar_risk_manager, qradar_security_information_and_event_manager, qradar_vulnerability_manager, smartcloud_entry_appliance, smartcloud_provisioning, software_defined_network_for_virtual_environments, starter_kit_for_cloud, workload_deployer, security_access_manager_for_mobile_8.0_firmware, security_access_manager_for_web_7.0_firmware, security_access_manager_for_web_8.0_firmware, storwize_v7000_firmware, storwize_v5000_firmware, storwize_v3700_firmware, storwize_v3500_firmware, flex_system_v7000_firmware, san_volume_controller_firmware, stn6500_firmware, stn6800_firmware, stn7800_firmware, ubuntu_linux, zenworks_configuration_management, open_enterprise_server, security_gateway, big-ip_access_policy_manager, big-ip_advanced_firewall_manager, big-ip_analytics, big-ip_application_acceleration_manager, big-ip_application_security_manager, big-ip_edge_gateway, big-ip_global_traffic_manager, big-ip_link_controller, big-ip_local_traffic_manager, big-ip_policy_enforcement_manager, big-ip_protocol_security_module, big-ip_wan_optimization_manager, big-ip_webaccelerator, big-iq_cloud, big-iq_device, big-iq_security, enterprise_manager, traffix_signaling_delivery_controller, arx_firmware, netscaler_sdx_firmware, mac_os_x, vcenter_server_appliance, esx

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Known exploits

Data from CISA

Vulnerability name
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Exploit added on
Jan 28, 2022
Exploit action due
Jul 28, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-78
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-78

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.