PT-2014-9087 · Gnu+8 · Bash+9

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-7187

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions bash versions prior to 4.3 bash-3.2 bash-4.1.2 bash-4.2.45 bash-debuginfo bash-debuginfo-3.2 bash-debuginfo-4.1.2 bash-debuginfo-4.2.45 bash-debugsource bash-devel bash-doc bash-doc-4.1.2 bash-doc-4.2.45 bash-loadables bash-loadables-debuginfo
Description The issue is related to multiple vulnerabilities in the bash package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The problem is caused by an off-by-one error in the read token word function in parse.y, allowing remote attackers to cause a denial of service or possibly have other unspecified impacts. The vulnerability may also allow an attacker to inject commands into a Bash shell, depending on how the shell is invoked.
Recommendations For bash versions prior to 4.3, update to version 4.3 or later. For bash-3.2, update to a newer version. For bash-4.1.2, update to a newer version. For bash-4.2.45, update to a newer version. For bash-debuginfo, update to a newer version. For bash-debuginfo-3.2, update to a newer version. For bash-debuginfo-4.1.2, update to a newer version. For bash-debuginfo-4.2.45, update to a newer version. For bash-debugsource, update to a newer version. For bash-devel, update to a newer version. For bash-doc, update to a newer version. For bash-doc-4.1.2, update to a newer version. For bash-doc-4.2.45, update to a newer version. For bash-loadables, update to a newer version. For bash-loadables-debuginfo, update to a newer version. As a temporary workaround, consider disabling the read token word function until a patch is available. Restrict access to the vulnerable bash package to minimize the risk of exploitation. Avoid using the bash shell until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2200
ALT-PU-2014-2201
BDU:2014-00320
BDU:2015-05950
BDU:2015-05951
BDU:2015-05952
BDU:2015-05953
BDU:2015-05954
BDU:2015-05955
BDU:2015-05956
BDU:2015-05957
BDU:2015-05958
BDU:2015-06152
BDU:2015-06153
BDU:2015-06154
BDU:2015-06155
BDU:2015-06156
BDU:2015-06157
BDU:2015-06158
BDU:2015-06159
BDU:2015-06160
BDU:2015-09245
BDU:2015-09246
BDU:2015-09247
BDU:2015-09248
BDU:2015-09249
BDU:2015-09250
BDU:2015-09251
BDU:2015-09252
BDU:2015-09253
BDU:2015-09794
CESA-2014_1306
CVE-2014-7187
DLA-63-1
DSA-3035-1
MGASA-2014-0394
OPENSUSE-SU-2014_1229-1
OPENSUSE-SU-2014_1242-1
OPENSUSE-SU-2014_1254-1
OPENSUSE-SU-2024:10106-1
RHSA-2014:1306
RHSA-2014:1311
RHSA-2014:1312
RHSA-2014:1354
RHSA-2014:1865
RHSA-2014_1306
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2364-1

Affected Products

Alt Linux
Centos
Cisco Ios Xe
Cisco Nexus
Huawei Vrp
Red Hat
Suse
Ubuntu
Vmware Vcenter
Bash