CVE-2014-6277

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
gnubash
1.14.0
gnubash
1.14.1
gnubash
1.14.2
gnubash
1.14.3
gnubash
1.14.4
gnubash
1.14.5
gnubash
1.14.6
gnubash
1.14.7
gnubash
2.0
gnubash
2.01
gnubash
2.01.1
gnubash
2.02
gnubash
2.02.1
gnubash
2.03
gnubash
2.04
gnubash
2.05
gnubash
2.05:a
gnubash
2.05:b
gnubash
3.0
gnubash
3.0.16
gnubash
3.1
gnubash
3.2
gnubash
3.2.48
gnubash
4.0
gnubash
4.0:rc1
gnubash
4.1
gnubash
4.2
gnubash
4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bash
bookworm
5.2.15-2
fixed
bullseye
5.1-2+deb11u1
fixed
sid
5.2.32-1
fixed
trixie
5.2.32-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bash
lucid
Fixed 4.1-2ubuntu3.5
released
precise
Fixed 4.2-2ubuntu2.6
released
trusty
Fixed 4.3-7ubuntu1.5
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bash
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 12 SP1
4.2-82.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 12 SP1
4.2-82.1
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-devel
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-doc
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 12 SP1
4.2-82.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 12 SP1
4.2-82.1
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-lang
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
libreadline6
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
libreadline6-32bit
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
libreadline7
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed
readline-devel
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed
readline-doc
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 12 SP1
6.2-82.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 12 SP1
6.2-82.1
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed
References