PT-2014-1176 · Gnu+5 · Bash+6
Lastc0De
·
Published
2014-09-24
·
Updated
2026-01-04
·
CVE-2014-6278
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
bash versions 1.14 through 4.2 p52
GNU Bash (affected versions not specified)
Description
The issue is related to the way shell functions are passed through environment variables, allowing an attacker to inject commands into a Bash shell. This can be exploited by creating a new environment variable, which can be done remotely or locally. The vulnerability may allow an unauthenticated remote attacker to execute commands on an affected server, depending on how the shell is invoked. The Bash shell may be invoked by various processes, including telnet, SSH, DHCP, and scripts hosted on web servers.
Recommendations
For bash versions 1.14 through 4.2 p52, update to a version later than 4.2 p52 to resolve the issue.
For GNU Bash, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of environment variables to minimize the risk of exploitation. Avoid using the
environment variables in the affected bash shell until the issue is resolved.Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Cisco Ios Xe
Cisco Nexus
Suse
Ubuntu
Vmware Vcenter
Bash