PT-2014-9088 · Gnu+7 · Bash+8

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-7186

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions bash versions prior to 4.3 bash-3.2 bash-3.0 bash-4.1.2 bash-4.2.45 bash-debuginfo bash-debuginfo-3.2 bash-debuginfo-4.1.2 bash-debuginfo-4.2.45 bash-debugsource bash-devel bash-doc bash-doc-4.1.2 bash-doc-4.2.45 bash-loadables bash-loadables-debuginfo bash-lang
Description The issue is related to the way in which shell functions are passed through environment variables in GNU Bash. This may allow an attacker to inject commands into a Bash shell, depending on how the shell is invoked. The Bash shell may be invoked by a number of processes including, but not limited to, telnet, SSH, DHCP, and scripts hosted on web servers. The vulnerability can be exploited remotely and may lead to a denial of service or potentially allow the execution of arbitrary code.
Recommendations For bash versions prior to 4.3, update to version 4.3 or later. For bash-3.2, update to a version later than 3.2. For bash-3.0, update to a version later than 3.0. For bash-4.1.2, update to a version later than 4.1.2. For bash-4.2.45, update to a version later than 4.2.45. For bash-debuginfo, bash-debuginfo-3.2, bash-debuginfo-4.1.2, bash-debuginfo-4.2.45, update to a version that includes the fix for the vulnerability. For bash-debugsource, bash-devel, bash-doc, bash-doc-4.1.2, bash-doc-4.2.45, bash-loadables, bash-loadables-debuginfo, bash-lang, update to a version that includes the fix for the vulnerability. As a temporary workaround, consider restricting access to the Bash shell and limiting the invocation of shell functions through environment variables.

Exploit

Fix

DoS

Buffer Overflow

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2200
ALT-PU-2014-2201
BDU:2014-00321
BDU:2015-05950
BDU:2015-05951
BDU:2015-05952
BDU:2015-05953
BDU:2015-05954
BDU:2015-05955
BDU:2015-05956
BDU:2015-05957
BDU:2015-05958
BDU:2015-06152
BDU:2015-06153
BDU:2015-06154
BDU:2015-06155
BDU:2015-06156
BDU:2015-06157
BDU:2015-06158
BDU:2015-06159
BDU:2015-06160
BDU:2015-09245
BDU:2015-09246
BDU:2015-09247
BDU:2015-09248
BDU:2015-09249
BDU:2015-09250
BDU:2015-09251
BDU:2015-09252
BDU:2015-09253
BDU:2015-09794
CESA-2014_1306
CVE-2014-7186
DLA-63-1
DSA-3035-1
MGASA-2014-0394
OPENSUSE-SU-2014_1229-1
OPENSUSE-SU-2014_1242-1
OPENSUSE-SU-2014_1254-1
OPENSUSE-SU-2024:10106-1
RHSA-2014:1306
RHSA-2014:1311
RHSA-2014:1312
RHSA-2014:1354
RHSA-2014:1865
RHSA-2014_1306
USN-2364-1

Affected Products

Alt Linux
Centos
Cisco Ios Xe
Cisco Nexus
Red Hat
Suse
Ubuntu
Vmware Vcenter
Bash