CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 09, 2014
- Published Date
- September 24, 2014
- Last Updated
- February 07, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CVSS Scores
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-28 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/smtp/qmail_bash_env_exec.rb | 2025-04-29 11:01:27 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2014/CVE-2014-6271.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
vmware_bash_function_root
Type: metasploit • Created: Unknown
qmail_bash_env_exec
Type: metasploit • Created: Unknown
bash_environment
Type: metasploit • Created: Unknown
advantech_switch_bash_env_exec
Type: metasploit • Created: Unknown
pureftpd_bash_env_exec
Type: metasploit • Created: Unknown
ipfire_bashbug_exec
Type: metasploit • Created: Unknown
YunchoHang/CVE-2014-6271-SHELLSHOCK
Type: github • Created: 2025-02-26 10:36:45 UTC • Stars: 0
RadYio/CVE-2014-6271
Type: github • Created: 2024-11-26 09:07:24 UTC • Stars: 0
K3ysTr0K3R/CVE-2014-6271-EXPLOIT
Type: github • Created: 2024-05-18 19:42:58 UTC • Stars: 2
0xN7y/CVE-2014-6271
Type: github • Created: 2023-10-31 06:48:30 UTC • Stars: 1
hanmin0512/CVE-2014-6271_pwnable
Type: github • Created: 2023-08-29 06:58:26 UTC • Stars: 0
Jsmoreira02/CVE-2014-6271
Type: github • Created: 2023-07-01 03:50:02 UTC • Stars: 0
Brandaoo/CVE-2014-6271
Type: github • Created: 2023-03-25 05:32:59 UTC • Stars: 0
mritunjay-k/CVE-2014-6271
Type: github • Created: 2023-03-02 17:30:03 UTC • Stars: 0
FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-
Type: github • Created: 2022-09-09 10:44:25 UTC • Stars: 0
b4keSn4ke/CVE-2014-6271
Type: github • Created: 2021-07-29 04:51:43 UTC • Stars: 14
mochizuki875/CVE-2014-6271-Apache-Debian
Type: github • Created: 2021-07-24 07:47:55 UTC • Stars: 1
MuirlandOracle/CVE-2014-6271-IPFire
Type: github • Created: 2020-11-12 04:12:55 UTC • Stars: 0
cyberharsh/Shellbash-CVE-2014-6271
Type: github • Created: 2020-06-26 11:08:22 UTC • Stars: 0
Dilith006/CVE-2014-6271
Type: github • Created: 2020-05-12 18:37:14 UTC • Stars: 0
rashmikadileeshara/CVE-2014-6271-Shellshock-
Type: github • Created: 2020-05-12 17:51:06 UTC • Stars: 0
Any3ite/CVE-2014-6271
Type: github • Created: 2020-01-06 08:24:35 UTC • Stars: 1
Sindayifu/CVE-2019-14287-CVE-2014-6271
Type: github • Created: 2019-11-13 14:17:19 UTC • Stars: 0
shawntns/exploit-CVE-2014-6271
Type: github • Created: 2019-04-27 18:55:39 UTC • Stars: 0
Aruthw/CVE-2014-6271
Type: github • Created: 2018-06-30 13:26:20 UTC • Stars: 0
w4fz5uck5/ShockZaum-CVE-2014-6271
Type: github • Created: 2018-06-18 16:09:15 UTC • Stars: 0
kowshik-sundararajan/CVE-2014-6271
Type: github • Created: 2018-05-05 05:50:50 UTC • Stars: 0
0x00-0x00/CVE-2014-6271
Type: github • Created: 2017-11-23 14:45:22 UTC • Stars: 3
zalalov/CVE-2014-6271
Type: github • Created: 2017-04-30 19:47:00 UTC • Stars: 6
Pilou-Pilou/docker_CVE-2014-6271.
Type: github • Created: 2017-01-25 21:51:52 UTC • Stars: 0
opsxcq/exploit-CVE-2014-6271
Type: github • Created: 2016-12-07 23:38:50 UTC • Stars: 211
ryeyao/CVE-2014-6271_Test
Type: github • Created: 2014-09-29 13:16:08 UTC • Stars: 1
u20024804/bash-4.3-fixed-CVE-2014-6271
Type: github • Created: 2014-09-27 22:22:41 UTC • Stars: 0
u20024804/bash-4.2-fixed-CVE-2014-6271
Type: github • Created: 2014-09-27 22:22:27 UTC • Stars: 0
u20024804/bash-3.2-fixed-CVE-2014-6271
Type: github • Created: 2014-09-27 21:29:23 UTC • Stars: 0
villadora/CVE-2014-6271
Type: github • Created: 2014-09-26 04:15:15 UTC • Stars: 0
woltage/CVE-2014-6271
Type: github • Created: 2014-09-25 13:06:50 UTC • Stars: 0
ilismal/Nessus_CVE-2014-6271_check
Type: github • Created: 2014-09-25 09:02:42 UTC • Stars: 0
mattclegg/CVE-2014-6271
Type: github • Created: 2014-09-25 08:10:26 UTC • Stars: 0
jblaine/cookbook-bash-CVE-2014-6271
Type: github • Created: 2014-09-25 00:11:01 UTC • Stars: 0