PT-2014-9086 · Apache +9 · Apache Http Server +10

Kyle George

·

Published

1970-01-01

·

Updated

2025-12-30

·

CVE-2014-6271

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bash versions prior to 4.2.45-alt2 Bash versions prior to 3.2.51-alt3 PAN-OS and Panorama versions 5.0.14 and earlier PAN-OS and Panorama versions 5.1.9 and earlier PAN-OS and Panorama versions 6.0.5 and earlier PAN-OS and Panorama versions 6.1.0 and earlier
Description Bash is vulnerable to remote code execution due to flaws in how it evaluates environment variables. An attacker can exploit this by crafting malicious environment variables to override restrictions and execute arbitrary shell commands. This vulnerability affects systems where environment variables can be controlled by external actors, such as through SSH or web servers. The vulnerability can be exploited through multiple vectors. Successful exploitation does not necessarily result in root access, but rather execution with the privileges of the logged-in user. The vulnerability exists in
bash
and affects versions prior to 4.2.45-alt2 and 3.2.51-alt3. Additionally, PAN-OS and Panorama versions 5.0.14 and earlier, 5.1.9 and earlier, 6.0.5 and earlier, and 6.1.0 and earlier are also affected. The vulnerability stems from incorrect handling of trailing code in function definitions, allowing attackers to bypass environment restrictions.
Recommendations Update Bash to version 4.2.45-alt2 or later. Update Bash to version 3.2.51-alt3 or later. Update PAN-OS and Panorama to a version later than 6.1.0. Run
sudo pro fix USN-2362-1
to apply the fix for Ubuntu systems.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2014-1451
ALT-PU-2014-1734
ALT-PU-2014-2179
ALT-PU-2014-2180
ALT-PU-2014-2195
ALT-PU-2014-2200
ALT-PU-2014-2201
ALT-PU-2014-2376
ALT-PU-2014-2476
ALT-PU-2015-1023
ALT-PU-2015-1186
ALT-PU-2015-1849
ALT-PU-2015-2113
ALT-PU-2016-1086
ALT-PU-2016-1200
ALT-PU-2016-1438
ALT-PU-2016-1439
ALT-PU-2016-1623
ALT-PU-2016-2124
ALT-PU-2016-2128
ALT-PU-2016-2139
ALT-PU-2016-2147
ALT-PU-2018-1001
ALT-PU-2018-1002
ALT-PU-2018-1023
ALT-PU-2018-1025
ALT-PU-2018-1046
ALT-PU-2018-1047
ALT-PU-2018-1048
ALT-PU-2018-1111
ALT-PU-2018-1112
ALT-PU-2018-1124
ALT-PU-2018-1226
ALT-PU-2018-1253
ALT-PU-2018-1611
ALT-PU-2018-2044
ALT-PU-2018-2045
ALT-PU-2018-2046
ALT-PU-2018-2222
ALT-PU-2018-2253
ALT-PU-2018-2289
ALT-PU-2018-2448
ALT-PU-2018-2598
ALT-PU-2019-1081
ALT-PU-2019-2016
ALT-PU-2019-2054
ALT-PU-2019-2120
ALT-PU-2019-2246
ALT-PU-2019-2247
ALT-PU-2019-2296
ALT-PU-2019-2311
ALT-PU-2019-2314
ALT-PU-2019-2339
ALT-PU-2019-2746
ALT-PU-2019-3161
ALT-PU-2019-3221
ALT-PU-2020-1918
ALT-PU-2020-1950
ALT-PU-2020-2003
ALT-PU-2020-2030
ALT-PU-2020-2031
ALT-PU-2020-2091
ALT-PU-2020-2149
ALT-PU-2020-2153
ALT-PU-2020-2155
ALT-PU-2020-2158
ALT-PU-2020-2162
ALT-PU-2020-2164
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2020-2688
ALT-PU-2020-2716
ALT-PU-2020-2757
ALT-PU-2020-2770
ALT-PU-2020-2825
ALT-PU-2020-2826
ALT-PU-2020-2858
ALT-PU-2020-2892
ALT-PU-2020-2918
ALT-PU-2020-2935
ALT-PU-2020-2936
ALT-PU-2020-2949
ALT-PU-2020-3057
ALT-PU-2020-3078
ALT-PU-2020-3096
ALT-PU-2020-3210
ALT-PU-2020-3213
ALT-PU-2020-3238
ALT-PU-2020-3454
ALT-PU-2020-3536
ALT-PU-2020-3553
ALT-PU-2020-3571
ALT-PU-2021-1083
ALT-PU-2021-1093
ALT-PU-2021-1105
ALT-PU-2021-1128
ALT-PU-2021-1376
ALT-PU-2021-1446
ALT-PU-2021-1447
ALT-PU-2021-1525
ALT-PU-2021-1531
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1698
ALT-PU-2021-1706
ALT-PU-2021-1707
ALT-PU-2021-1711
ALT-PU-2021-1720
ALT-PU-2021-1739
ALT-PU-2021-1745
ALT-PU-2021-1763
ALT-PU-2021-1768
ALT-PU-2021-1776
ALT-PU-2021-1833
ALT-PU-2021-1840
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1869
ALT-PU-2021-1870
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2021-1974
ALT-PU-2021-1983
ALT-PU-2021-1993
ALT-PU-2021-2007
ALT-PU-2021-2050
ALT-PU-2021-2068
ALT-PU-2021-2097
ALT-PU-2021-2141
ALT-PU-2021-2150
ALT-PU-2021-2199
ALT-PU-2021-2210
ALT-PU-2021-2214
ALT-PU-2021-2220
ALT-PU-2021-2284
ALT-PU-2021-2288
ALT-PU-2021-2289
ALT-PU-2021-2297
ALT-PU-2021-2298
ALT-PU-2021-2312
ALT-PU-2021-2314
ALT-PU-2021-2315
ALT-PU-2021-2326
ALT-PU-2021-2330
ALT-PU-2021-2334
ALT-PU-2021-2355
ALT-PU-2021-2363
ALT-PU-2021-2365
ALT-PU-2021-2395
ALT-PU-2021-2486
ALT-PU-2021-2616
ALT-PU-2021-2643
ALT-PU-2021-2644
ALT-PU-2021-2658
ALT-PU-2021-2659
ALT-PU-2021-2661
ALT-PU-2021-2662
ALT-PU-2021-2671
ALT-PU-2021-2691
ALT-PU-2021-2748
ALT-PU-2021-2778
ALT-PU-2021-2858
ALT-PU-2021-2901
ALT-PU-2021-2902
ALT-PU-2021-2912
ALT-PU-2021-2915
ALT-PU-2021-2919
ALT-PU-2021-2926
ALT-PU-2021-2938
ALT-PU-2021-2984
ALT-PU-2021-3000
ALT-PU-2021-3002
ALT-PU-2021-3007
ALT-PU-2021-3019
ALT-PU-2021-3041
ALT-PU-2021-3055
ALT-PU-2021-3220
ALT-PU-2021-3222
ALT-PU-2021-3230
ALT-PU-2021-3232
ALT-PU-2021-3233
ALT-PU-2021-3268
ALT-PU-2021-3270
ALT-PU-2021-3271
ALT-PU-2021-3282
ALT-PU-2021-3309
ALT-PU-2021-3375
ALT-PU-2021-3376
ALT-PU-2021-3380
ALT-PU-2021-3415
ALT-PU-2021-3430
ALT-PU-2021-3444
ALT-PU-2021-3451
ALT-PU-2021-3458
ALT-PU-2021-3468
ALT-PU-2021-3469
ALT-PU-2021-3477
ALT-PU-2021-3481
ALT-PU-2021-3485
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2021-4855
ALT-PU-2022-1104
ALT-PU-2022-1105
ALT-PU-2022-1108
ALT-PU-2022-1135
ALT-PU-2022-1137
ALT-PU-2022-1138
ALT-PU-2022-1139
ALT-PU-2022-1140
ALT-PU-2022-1174
ALT-PU-2022-1190
ALT-PU-2022-1192
ALT-PU-2022-1197
ALT-PU-2022-1221
ALT-PU-2022-1223
ALT-PU-2022-1239
ALT-PU-2022-1240
ALT-PU-2022-1243
ALT-PU-2022-1267
ALT-PU-2022-1289
ALT-PU-2022-1297
ALT-PU-2022-1298
ALT-PU-2022-1300
ALT-PU-2022-1301
ALT-PU-2022-1346
ALT-PU-2022-1370
ALT-PU-2022-1387
ALT-PU-2022-1388
ALT-PU-2022-1410
ALT-PU-2022-1411
ALT-PU-2022-1413
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2022-1428
ALT-PU-2022-1432
ALT-PU-2022-1441
ALT-PU-2022-1456
ALT-PU-2022-1461
ALT-PU-2022-1462
ALT-PU-2022-1467
ALT-PU-2022-1489
ALT-PU-2022-1496
ALT-PU-2022-1506
ALT-PU-2022-1515
ALT-PU-2022-1518
ALT-PU-2022-1531
ALT-PU-2022-1540
ALT-PU-2022-1543
ALT-PU-2022-1562
ALT-PU-2022-1563
ALT-PU-2022-1592
ALT-PU-2022-1611
ALT-PU-2022-1630
ALT-PU-2022-1633
ALT-PU-2022-1647
ALT-PU-2022-1659
ALT-PU-2022-1668
ALT-PU-2022-1678
ALT-PU-2022-1679
ALT-PU-2022-1680
ALT-PU-2022-1688
ALT-PU-2022-1706
ALT-PU-2022-1730
ALT-PU-2022-1739
ALT-PU-2022-1746
ALT-PU-2022-1760
ALT-PU-2022-1768
ALT-PU-2022-1797
ALT-PU-2022-1799
ALT-PU-2022-1810
ALT-PU-2022-1811
ALT-PU-2022-1816
ALT-PU-2022-1823
ALT-PU-2022-1824
ALT-PU-2022-1826
ALT-PU-2022-1830
ALT-PU-2022-1833
ALT-PU-2022-1835
ALT-PU-2022-1853
ALT-PU-2022-1873
ALT-PU-2022-1880
ALT-PU-2022-1881
ALT-PU-2022-1907
ALT-PU-2022-1929
ALT-PU-2022-2002
ALT-PU-2022-2003
ALT-PU-2022-2014
ALT-PU-2022-2027
ALT-PU-2022-2037
ALT-PU-2022-2038
ALT-PU-2022-2050
ALT-PU-2022-2052
ALT-PU-2022-2054
ALT-PU-2022-2061
ALT-PU-2022-2067
ALT-PU-2022-2096
ALT-PU-2022-2099
ALT-PU-2022-2113
ALT-PU-2022-2132
ALT-PU-2022-2136
ALT-PU-2022-2137
ALT-PU-2022-2139
ALT-PU-2022-2152
ALT-PU-2022-2155
ALT-PU-2022-2156
ALT-PU-2022-2158
ALT-PU-2022-2167
ALT-PU-2022-2171
ALT-PU-2022-2174
ALT-PU-2022-2232
ALT-PU-2022-2233
ALT-PU-2022-2248
ALT-PU-2022-2250
ALT-PU-2022-2256
ALT-PU-2022-2258
ALT-PU-2022-2261
ALT-PU-2022-2265
ALT-PU-2022-2288
ALT-PU-2022-2305
ALT-PU-2022-2339
ALT-PU-2022-2340
ALT-PU-2022-2342
ALT-PU-2022-2344
ALT-PU-2022-2360
ALT-PU-2022-2361
ALT-PU-2022-2362
ALT-PU-2022-2364
ALT-PU-2022-2365
ALT-PU-2022-2370
ALT-PU-2022-2407
ALT-PU-2022-2417
ALT-PU-2022-2418
ALT-PU-2022-2426
ALT-PU-2022-2434
ALT-PU-2022-2436
ALT-PU-2022-2445
ALT-PU-2022-2446
ALT-PU-2022-2477
ALT-PU-2022-2506
ALT-PU-2022-2512
ALT-PU-2022-2552
ALT-PU-2022-2633
ALT-PU-2022-2635
ALT-PU-2022-2666
ALT-PU-2022-2682
ALT-PU-2022-2691
ALT-PU-2022-2692
ALT-PU-2022-2873
ALT-PU-2022-2883
ALT-PU-2022-2884
ALT-PU-2022-2885
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2022-2984
ALT-PU-2022-3072
ALT-PU-2022-3073
ALT-PU-2022-3102
ALT-PU-2022-3232
ALT-PU-2023-1066
ALT-PU-2023-1299
ALT-PU-2023-1461
ALT-PU-2023-1518
ALT-PU-2023-1583
ALT-PU-2023-1684
ALT-PU-2023-1687
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-1912
ALT-PU-2023-4266
ALT-PU-2023-4894
ALT-PU-2023-6462
ALT-PU-2023-7320
ALT-PU-2023-7463
ALT-PU-2023-7647
ALT-PU-2023-7888
ALT-PU-2023-8058
ALT-PU-2024-14046
ALT-PU-2024-1563
ALT-PU-2024-16002
ALT-PU-2024-16022
ALT-PU-2024-16072
ALT-PU-2024-17211
ALT-PU-2024-1973
ALT-PU-2024-2598
ALT-PU-2024-3474
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4252
ALT-PU-2024-4467
ALT-PU-2024-7377
ALT-PU-2024-7812
ALT-PU-2024-9513
ALT-PU-2025-12647
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2014-00319
BDU:2015-00149
BDU:2015-00150
BDU:2015-00152
BDU:2015-00154
BDU:2015-00156
BDU:2015-00158
BDU:2015-00353
BDU:2015-04143
BDU:2015-04144
BDU:2015-04145
BDU:2015-04146
BDU:2015-04147
BDU:2015-04148
BDU:2015-05950
BDU:2015-05951
BDU:2015-05952
BDU:2015-05953
BDU:2015-05954
BDU:2015-05955
BDU:2015-05956
BDU:2015-05957
BDU:2015-05958
BDU:2015-09793
BDU:2015-09818
CESA-2014_0376
CESA-2014_0625
CESA-2014_0626
CESA-2014_1293
CESA-2014_1306
CESA-2015_0066
CESA-2016_0722
CESA-2016_0996
CESA-2016_2098
CESA-2016_2105
CESA-2017_2029
CESA-2017_2563
CESA-2017_3080
CESA-2017_3081
CESA-2018_0023
CESA-2018_0151
CESA-2018_0512
CESA-2018_1062
CESA-2018_1319
CESA-2019_0711
CESA-2019_2143
CESA-2019_2405
CESA-2019_2411
CESA-2019_3286
CESA-2019_3287
CESA-2019_3702
CESA-2019_3735
CESA-2019_3736
CESA-2020_0855
CESA-2020_0912
CESA-2020_2530
CESA-2020_3915
CESA-2020_3936
CESA-2020_4060
CESA-2020_4286
CESA-2020_4289
CESA-2020_4331
CESA-2020_4431
CESA-2020_4609
CESA-2020_4670
CESA-2020_4847
CESA-2021_0537
CESA-2021_0558
CESA-2021_0851
CESA-2021_0856
CESA-2021_1578
CESA-2021_1739
CESA-2021_1846
CESA-2021_2714
CESA-2021_2715
CESA-2021_2716
CESA-2021_2725
CESA-2021_3044
CESA-2021_3057
CESA-2021_3076
CESA-2021_3088
CESA-2021_3327
CESA-2021_4140
CESA-2021_4142
CESA-2021_4226
CESA-2021_4356
CESA-2021_4645
CESA-2021_4646
CESA-2021_4647
CESA-2022_0176
CESA-2022_0188
CESA-2022_0232
CESA-2022_0267
CESA-2022_0274
CESA-2022_0819
CESA-2022_0825
CESA-2022_0849
CESA-2022_1065
CESA-2022_1066
CESA-2022_1535
CESA-2022_1550
CESA-2022_1555
CESA-2022_1642
CESA-2022_1819
CESA-2022_1975
CESA-2022_1988
CESA-2022_2201
CESA-2022_2213
CESA-2022_4642
CESA-2022_5219
CESA-2022_5232
CESA-2022_5316
CESA-2022_5326
CESA-2022_5344
CESA-2022_5818
CESA-2022_5819
CESA-2022_5834
CESA-2022_5839
CESA-2022_7106
CESA-2022_7110
CESA-2022_7134
CESA-2022_7137
CESA-2022_7444
CESA-2022_7683
CESA-2022_7793
CESA-2022_7813
CESA-2023_1095
CESA-2023_2736
CESA-2023_2951
CESA-2024_2950
CESA-2024_2987
CESA-2024_2988
CESA-2024_3138
CESA-2024_3166
CESA-2024_3618
CESA-2024_5101
CESA-2024_5102
CESA-2024_7000
CESA-2024_7001
CESA-2025_1215
CESA-2025_1301
CESA-2025_1306
CESA-2025_1314
CESA-2025_1338
CESA-2025_7531
CESA-2025_7532
CVE-2014-6271
DLA-59-1
DSA-3032-1
ELSA-2014-1293
MGASA-2014-0388
OPENSUSE-SU-2014_1226-1
OPENSUSE-SU-2014_1229-1
OPENSUSE-SU-2014_1242-1
OPENSUSE-SU-2014_1254-1
OPENSUSE-SU-2024:10106-1
PAN-SA-2014-0004
RHSA-2014:1293
RHSA-2014:1294
RHSA-2014:1295
RHSA-2014:1354
RHSA-2014_0376
RHSA-2014_0624
RHSA-2014_0625
RHSA-2014_0626
RHSA-2014_0679
RHSA-2014_0680
RHSA-2014_1293
RHSA-2014_1306
RHSA-2015_0066
RHSA-2015_0800
RHSA-2016_0722
RHSA-2016_0996
RHSA-2016_2098
RHSA-2016_2105
RHSA-2016_2110
RHSA-2016_2124
RHSA-2017_0372
RHSA-2017_2029
RHSA-2017_2563
RHSA-2017_3080
RHSA-2017_3081
RHSA-2018_0016
RHSA-2018_0023
RHSA-2018_0151
RHSA-2018_0292
RHSA-2018_0512
RHSA-2018_1062
RHSA-2018_1196
RHSA-2018_1319
RHSA-2019_0711
RHSA-2019_2143
RHSA-2019_2405
RHSA-2019_2411
RHSA-2019_3286
RHSA-2019_3287
RHSA-2019_3702
RHSA-2019_3735
RHSA-2019_3736
RHSA-2020_0855
RHSA-2020_0912
RHSA-2020_2529
RHSA-2020_2530
RHSA-2020_3915
RHSA-2020_3936
RHSA-2020_4060
RHSA-2020_4062
RHSA-2020_4286
RHSA-2020_4289
RHSA-2020_4431
RHSA-2020_4609
RHSA-2020_4670
RHSA-2020_4847
RHSA-2021_0537
RHSA-2021_0558
RHSA-2021_0851
RHSA-2021_0856
RHSA-2021_0857
RHSA-2021_0860
RHSA-2021_1578
RHSA-2021_1739
RHSA-2021_1846
RHSA-2021_2714
RHSA-2021_2715
RHSA-2021_2725
RHSA-2021_2726
RHSA-2021_2735
RHSA-2021_3057
RHSA-2021_3076
RHSA-2021_3088
RHSA-2021_3327
RHSA-2021_3328
RHSA-2021_4140
RHSA-2021_4142
RHSA-2021_4226
RHSA-2021_4356
RHSA-2021_4646
RHSA-2021_4647
RHSA-2022_0176
RHSA-2022_0188
RHSA-2022_0267
RHSA-2022_0269
RHSA-2022_0274
RHSA-2022_0819
RHSA-2022_0825
RHSA-2022_1065
RHSA-2022_1066
RHSA-2022_1073
RHSA-2022_1417
RHSA-2022_1550
RHSA-2022_1555
RHSA-2022_1642
RHSA-2022_1819
RHSA-2022_1975
RHSA-2022_1988
RHSA-2022_2201
RHSA-2022_2213
RHSA-2022_2214
RHSA-2022_4584
RHSA-2022_4592
RHSA-2022_4642
RHSA-2022_4644
RHSA-2022_4899
RHSA-2022_5232
RHSA-2022_5236
RHSA-2022_5249
RHSA-2022_5267
RHSA-2022_5316
RHSA-2022_5326
RHSA-2022_5344
RHSA-2022_5818
RHSA-2022_5819
RHSA-2022_5834
RHSA-2022_6224
RHSA-2022_6582
RHSA-2022_6610
RHSA-2022_7106
RHSA-2022_7110
RHSA-2022_7134
RHSA-2022_7314
RHSA-2022_7337
RHSA-2022_7338
RHSA-2022_7343
RHSA-2022_7444
RHSA-2022_7683
RHSA-2022_7793
RHSA-2022_7813
RHSA-2022_7933
RHSA-2022_7954
RHSA-2022_8267
RHSA-2022_8291
RHSA-2022_8420
RHSA-2023_1095
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024_2394
RHSA-2024_2950
RHSA-2024_2987
RHSA-2024_2988
RHSA-2024_3138
RHSA-2024_3166
RHSA-2024_3618
RHSA-2024_5101
RHSA-2024_5102
RHSA-2024_7000
RHSA-2024_7001
RHSA-2024_9315
RHSA-2025_1210
RHSA-2025_1215
RHSA-2025_1300
RHSA-2025_1301
RHSA-2025_1306
RHSA-2025_1309
RHSA-2025_1314
RHSA-2025_1329
RHSA-2025_1338
RHSA-2025_1346
RHSA-2025_16880
RHSA-2025_6966
RHSA-2025_7531
RHSA-2025_7532
SUSE-SU-2014_1212-1
SUSE-SU-2014_1213-1
SUSE-SU-2014_1260-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_2699-1
SUSE-SU-2017_2700-1
USN-2362-1

Affected Products

Alt Linux
Apache Http Server
Bash
Centos
Check Point Gaia
Cisco Ios Xe
Cisco Nexus
Openssh Sshd
Red Hat
Suse
Ubuntu