CVE-2014-6278

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 09, 2014
Published Date
September 30, 2014
Last Updated
December 30, 2025
Vendor
n/a
Product
n/a
Description
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Tags
cisa

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0

10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:41:37 UTC) Source

References

http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 http://www-01.ibm.com/support/docview.wss?uid=swg21685749 http://marc.info/?l=bugtraq&m=141577137423233&w=2 https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts http://linux.oracle.com/errata/ELSA-2014-3093 http://marc.info/?l=bugtraq&m=142721162228379&w=2 http://marc.info/?l=bugtraq&m=142358026505815&w=2 http://www-01.ibm.com/support/docview.wss?uid=swg21686479 http://jvn.jp/en/jp/JVN55667175/index.html http://secunia.com/advisories/60433 http://marc.info/?l=bugtraq&m=141383026420882&w=2 http://marc.info/?l=bugtraq&m=141585637922673&w=2 http://packetstormsecurity.com/files/137344/Sun-Secure-Global-Desktop-Oracle-Global-Desktop-Shellshock.html http://marc.info/?l=bugtraq&m=141576728022234&w=2 http://www-01.ibm.com/support/docview.wss?uid=swg21685541 http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html http://secunia.com/advisories/61816 http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html http://secunia.com/advisories/61442 http://marc.info/?l=bugtraq&m=142358078406056&w=2 http://secunia.com/advisories/61283 https://kc.mcafee.com/corporate/index?page=content&id=SB10085 http://secunia.com/advisories/61654 http://www.ubuntu.com/usn/USN-2380-1 http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 http://secunia.com/advisories/62312 https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html http://marc.info/?l=bugtraq&m=141879528318582&w=2 https://security-tracker.debian.org/tracker/CVE-2014-6278 http://www-01.ibm.com/support/docview.wss?uid=swg21685604 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://secunia.com/advisories/61703 http://secunia.com/advisories/61065 http://marc.info/?l=bugtraq&m=141383196021590&w=2 http://marc.info/?l=bugtraq&m=141383081521087&w=2 http://www-01.ibm.com/support/docview.wss?uid=swg21686445 http://www-01.ibm.com/support/docview.wss?uid=swg21686131 http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 http://marc.info/?l=bugtraq&m=141879528318582&w=2 http://secunia.com/advisories/61641 https://www.exploit-db.com/exploits/39887/ https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 http://www-01.ibm.com/support/docview.wss?uid=swg21685914 http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 http://marc.info/?l=bugtraq&m=142721162228379&w=2 http://secunia.com/advisories/60325 http://secunia.com/advisories/60024 http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash https://bugzilla.redhat.com/show_bug.cgi?id=1147414 http://secunia.com/advisories/62343 http://secunia.com/advisories/61565 https://www.suse.com/support/shellshock/ http://marc.info/?l=bugtraq&m=141450491804793&w=2 http://secunia.com/advisories/61313 http://marc.info/?l=bugtraq&m=142358026505815&w=2 http://secunia.com/advisories/61485 https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 http://marc.info/?l=bugtraq&m=141577297623641&w=2 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 http://marc.info/?l=bugtraq&m=141383244821813&w=2 http://secunia.com/advisories/61312 http://linux.oracle.com/errata/ELSA-2014-3094 http://secunia.com/advisories/60193 http://www.vmware.com/security/advisories/VMSA-2014-0010.html http://secunia.com/advisories/60063 http://secunia.com/advisories/60034 http://secunia.com/advisories/59907 http://secunia.com/advisories/58200 http://marc.info/?l=bugtraq&m=141577241923505&w=2 http://secunia.com/advisories/61643 http://www.novell.com/support/kb/doc.php?id=7015721 http://www-01.ibm.com/support/docview.wss?uid=swg21687079 http://secunia.com/advisories/61503 http://www-01.ibm.com/support/docview.wss?uid=swg21686246 http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 http://support.novell.com/security/cve/CVE-2014-6278.html http://marc.info/?l=bugtraq&m=141383465822787&w=2 http://www.qnap.com/i/en/support/con_show.php?cid=61 http://secunia.com/advisories/61552 http://secunia.com/advisories/61780 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 https://support.citrix.com/article/CTX200223 https://www.exploit-db.com/exploits/39568/ http://marc.info/?l=bugtraq&m=141330468527613&w=2 http://secunia.com/advisories/60044 http://secunia.com/advisories/61291 http://marc.info/?l=bugtraq&m=141345648114150&w=2 http://secunia.com/advisories/61287 http://marc.info/?l=bugtraq&m=141383353622268&w=2 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 http://marc.info/?l=bugtraq&m=141383304022067&w=2 http://secunia.com/advisories/61128 https://support.citrix.com/article/CTX200217 http://secunia.com/advisories/61471 http://secunia.com/advisories/60055 http://secunia.com/advisories/59961 http://secunia.com/advisories/61550 http://secunia.com/advisories/61633 http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html http://www-01.ibm.com/support/docview.wss?uid=swg21686494 https://kb.bluecoat.com/index?page=content&id=SA82 http://secunia.com/advisories/61328 http://www-01.ibm.com/support/docview.wss?uid=swg21685733 http://secunia.com/advisories/61129 http://secunia.com/advisories/61603 http://secunia.com/advisories/61857 http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:41:37 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

apache_mod_cgi_bash_env_exec

Type: metasploit • Created: Unknown

Metasploit module for CVE-2014-6278

cups_bash_env_exec

Type: metasploit • Created: Unknown

Metasploit module for CVE-2014-6278

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Metasploit

  • Added to KEVIntel