PT-2014-1175 · Gnu+4 · Bash+5
Stéphane Chazelas
·
Published
2014-09-24
·
Updated
2025-10-03
·
CVE-2014-6277
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
bash versions 1.14 through 4.2 p52
GNU Bash (affected versions not specified)
Description
The issue is related to errors in processing input data during code syntax analysis in the Bash shell. Exploitation of the vulnerability allows an attacker to execute arbitrary commands with the rights of the current user by creating a specially crafted environment variable. This can be done remotely, for example, using a web server or DHCP server, or locally. The vulnerability may lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations
For bash versions 1.14 through 4.2 p52, update to a version later than 4.2 p52 to resolve the issue.
For GNU Bash, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the Bash shell to minimize the risk of exploitation.
Avoid using the Bash shell for remote connections, such as telnet or SSH, until the issue is resolved.
Restrict access to web servers and DHCP servers that may be used to create a specially crafted environment variable.
Exploit
DoS
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe
Cisco Nexus
Suse
Ubuntu
Vmware Vcenter
Bash