CVE-2014-7169

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 24, 2014
Published Date
September 25, 2014
Last Updated
February 10, 2025
Vendor
n/a
Product
n/a
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVSS Scores

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-01-28 00:00:00 UTC) Source

References

http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 http://www-01.ibm.com/support/docview.wss?uid=swg21685749 http://www.openwall.com/lists/oss-security/2014/09/24/32 http://marc.info/?l=bugtraq&m=141577137423233&w=2 http://marc.info/?l=bugtraq&m=141216668515282&w=2 https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts http://marc.info/?l=bugtraq&m=141383138121313&w=2 http://marc.info/?l=bugtraq&m=142721162228379&w=2 http://www.securityfocus.com/archive/1/533593/100/0/threaded http://marc.info/?l=bugtraq&m=142358026505815&w=2 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html http://www-01.ibm.com/support/docview.wss?uid=swg21686084 http://www-01.ibm.com/support/docview.wss?uid=swg21686479 http://secunia.com/advisories/61188 http://jvn.jp/en/jp/JVN55667175/index.html http://secunia.com/advisories/61676 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html http://secunia.com/advisories/60433 http://marc.info/?l=bugtraq&m=141383026420882&w=2 http://marc.info/?l=bugtraq&m=141585637922673&w=2 http://rhn.redhat.com/errata/RHSA-2014-1306.html http://marc.info/?l=bugtraq&m=141576728022234&w=2 http://www-01.ibm.com/support/docview.wss?uid=swg21685541 http://secunia.com/advisories/61715 http://www.ubuntu.com/usn/USN-2363-2 http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html http://secunia.com/advisories/61816 http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html http://secunia.com/advisories/61442 http://marc.info/?l=bugtraq&m=142358078406056&w=2 http://marc.info/?l=bugtraq&m=142805027510172&w=2 http://secunia.com/advisories/61283 http://marc.info/?l=bugtraq&m=142113462216480&w=2 https://kc.mcafee.com/corporate/index?page=content&id=SB10085 http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html http://secunia.com/advisories/61654 http://www.novell.com/support/kb/doc.php?id=7015701 http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 http://secunia.com/advisories/62312 http://secunia.com/advisories/59272 http://marc.info/?l=bugtraq&m=141319209015420&w=2 https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html http://marc.info/?l=bugtraq&m=141879528318582&w=2 http://rhn.redhat.com/errata/RHSA-2014-1312.html http://www-01.ibm.com/support/docview.wss?uid=swg21685604 http://www.ubuntu.com/usn/USN-2363-1 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://secunia.com/advisories/61703 http://support.apple.com/kb/HT6495 http://www.kb.cert.org/vuls/id/252743 http://secunia.com/advisories/61065 http://linux.oracle.com/errata/ELSA-2014-3075.html http://marc.info/?l=bugtraq&m=141383196021590&w=2 http://marc.info/?l=bugtraq&m=141383081521087&w=2 http://www-01.ibm.com/support/docview.wss?uid=swg21686445 http://support.novell.com/security/cve/CVE-2014-7169.html http://www-01.ibm.com/support/docview.wss?uid=swg21686131 http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 http://marc.info/?l=bugtraq&m=141879528318582&w=2 http://www.us-cert.gov/ncas/alerts/TA14-268A http://secunia.com/advisories/61641 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 https://access.redhat.com/node/1200223 http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html http://www-01.ibm.com/support/docview.wss?uid=swg21685914 http://seclists.org/fulldisclosure/2014/Oct/0 http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 http://secunia.com/advisories/61619 http://linux.oracle.com/errata/ELSA-2014-3078.html https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 http://marc.info/?l=bugtraq&m=142721162228379&w=2 http://secunia.com/advisories/60325 https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes http://secunia.com/advisories/60024 http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html https://www.exploit-db.com/exploits/34879/ http://secunia.com/advisories/61622 https://access.redhat.com/articles/1200223 http://secunia.com/advisories/62343 http://advisories.mageia.org/MGASA-2014-0393.html http://secunia.com/advisories/61565 https://www.suse.com/support/shellshock/ http://marc.info/?l=bugtraq&m=141450491804793&w=2 http://secunia.com/advisories/61313 http://marc.info/?l=bugtraq&m=142358026505815&w=2 http://secunia.com/advisories/61873 http://secunia.com/advisories/61485 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html http://secunia.com/advisories/61618 http://secunia.com/advisories/60947 https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 https://support.apple.com/kb/HT6535 http://marc.info/?l=bugtraq&m=141577297623641&w=2 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 http://marc.info/?l=bugtraq&m=141383244821813&w=2 http://secunia.com/advisories/61312 http://secunia.com/advisories/60193 http://www.vmware.com/security/advisories/VMSA-2014-0010.html http://secunia.com/advisories/61479 http://secunia.com/advisories/60063 http://secunia.com/advisories/60034 http://marc.info/?l=bugtraq&m=141330425327438&w=2 http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html http://secunia.com/advisories/59907 http://secunia.com/advisories/58200 http://marc.info/?l=bugtraq&m=141577241923505&w=2 http://secunia.com/advisories/61643 http://twitter.com/taviso/statuses/514887394294652929 http://www.novell.com/support/kb/doc.php?id=7015721 http://www-01.ibm.com/support/docview.wss?uid=swg21687079 http://secunia.com/advisories/61503 http://www-01.ibm.com/support/docview.wss?uid=swg21686246 http://rhn.redhat.com/errata/RHSA-2014-1354.html http://marc.info/?l=bugtraq&m=141216207813411&w=2 http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 http://marc.info/?l=bugtraq&m=141383465822787&w=2 http://www.qnap.com/i/en/support/con_show.php?cid=61 http://marc.info/?l=bugtraq&m=141694386919794&w=2 http://secunia.com/advisories/61552 http://secunia.com/advisories/61780 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 https://support.citrix.com/article/CTX200223 http://linux.oracle.com/errata/ELSA-2014-3077.html http://www-01.ibm.com/support/docview.wss?uid=swg21686447 http://secunia.com/advisories/62228 http://marc.info/?l=bugtraq&m=141330468527613&w=2 http://secunia.com/advisories/61855 http://marc.info/?l=bugtraq&m=141235957116749&w=2 http://secunia.com/advisories/60044 http://secunia.com/advisories/61291 http://marc.info/?l=bugtraq&m=141345648114150&w=2 http://secunia.com/advisories/59737 http://secunia.com/advisories/61287 http://marc.info/?l=bugtraq&m=141383353622268&w=2 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://marc.info/?l=bugtraq&m=142118135300698&w=2 http://secunia.com/advisories/61711 http://marc.info/?l=bugtraq&m=142113462216480&w=2 http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 http://marc.info/?l=bugtraq&m=141383304022067&w=2 http://rhn.redhat.com/errata/RHSA-2014-1311.html http://secunia.com/advisories/61128 http://www.debian.org/security/2014/dsa-3035 https://support.citrix.com/article/CTX200217 http://secunia.com/advisories/61471 http://secunia.com/advisories/60055 http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash http://secunia.com/advisories/61550 http://secunia.com/advisories/61633 http://www-01.ibm.com/support/docview.wss?uid=swg21686494 http://linux.oracle.com/errata/ELSA-2014-1306.html https://kb.bluecoat.com/index?page=content&id=SA82 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html http://secunia.com/advisories/61328 http://www-01.ibm.com/support/docview.wss?uid=swg21685733 http://secunia.com/advisories/61129 http://secunia.com/advisories/61700 http://secunia.com/advisories/61626 http://secunia.com/advisories/61603 http://secunia.com/advisories/61857 http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-01-28 00:00:00 UTC