PT-2014-1176 · Gnu+5 · Bash+6

Lastc0De

·

Published

2014-09-24

·

Updated

2026-01-04

·

CVE-2014-6278

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions bash versions 1.14 through 4.2 p52 GNU Bash (affected versions not specified)
Description The issue is related to the way shell functions are passed through environment variables, allowing an attacker to inject commands into a Bash shell. This can be exploited by creating a new environment variable, which can be done remotely or locally. The vulnerability may allow an unauthenticated remote attacker to execute commands on an affected server, depending on how the shell is invoked. The Bash shell may be invoked by various processes, including telnet, SSH, DHCP, and scripts hosted on web servers.
Recommendations For bash versions 1.14 through 4.2 p52, update to a version later than 4.2 p52 to resolve the issue. For GNU Bash, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of environment variables to minimize the risk of exploitation. Avoid using the environment variables in the affected bash shell until the issue is resolved.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2209
BDU:2014-00319
BDU:2015-09794
BDU:2015-09818
CVE-2014-6278
MGASA-2014-0394
OPENSUSE-SU-2024:10106-1
SUSE-SU-2016:2872-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2380-1

Affected Products

Alt Linux
Cisco Ios Xe
Cisco Nexus
Suse
Ubuntu
Vmware Vcenter
Bash