CVE-2014-7169

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
gnubash
𝑥
≤ 4.3
aristaeos
4.9.0 ≤
𝑥
< 4.9.12
aristaeos
4.10.0 ≤
𝑥
< 4.10.9
aristaeos
4.11.0 ≤
𝑥
< 4.11.11
aristaeos
4.12.0 ≤
𝑥
< 4.12.9
aristaeos
4.13.0 ≤
𝑥
< 4.13.9
aristaeos
4.14.0 ≤
𝑥
< 4.14.4f
qnapqts
𝑥
< 4.1.1
qnapqts
4.1.1
qnapqts
4.1.1:build_0927
mageiamageia
3.0
mageiamageia
4.0
redhatgluster_storage_server_for_on-premise
2.1
redhatvirtualization
3.4
redhatenterprise_linux
4.0
redhatenterprise_linux
5.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
5.9
redhatenterprise_linux_eus
6.4
redhatenterprise_linux_eus
6.5
redhatenterprise_linux_eus
7.3
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_for_ibm_z_systems
5.9_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
6.4_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
6.5_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.3_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.4_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.5_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.6_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.7_s390x:_s390x
redhatenterprise_linux_for_power_big_endian
5.0_ppc:_ppc
redhatenterprise_linux_for_power_big_endian
5.9_ppc:_ppc
redhatenterprise_linux_for_power_big_endian
6.0_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian
6.4_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian
7.0_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
6.5_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.3_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.4_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.5_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.6_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.7_ppc64:_ppc64
redhatenterprise_linux_for_scientific_computing
6.0
redhatenterprise_linux_for_scientific_computing
7.0
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
5.6
redhatenterprise_linux_server_aus
5.9
redhatenterprise_linux_server_aus
6.2
redhatenterprise_linux_server_aus
6.4
redhatenterprise_linux_server_aus
6.5
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_from_rhui
5.0
redhatenterprise_linux_server_from_rhui
6.0
redhatenterprise_linux_server_from_rhui
7.0
redhatenterprise_linux_server_tus
6.5
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
susestudio_onsite
1.3
opensuseopensuse
12.3
opensuseopensuse
13.1
opensuseopensuse
13.2
debiandebian_linux
7.0
ibminfosphere_guardium_database_activity_monitoring
8.2
ibminfosphere_guardium_database_activity_monitoring
9.0
ibminfosphere_guardium_database_activity_monitoring
9.1
ibmpureapplication_system
1.0.0.0 ≤
𝑥
≤ 1.0.0.4
ibmpureapplication_system
1.1.0.0 ≤
𝑥
≤ 1.1.0.4
ibmpureapplication_system
2.0.0.0
ibmqradar_risk_manager
7.1.0
ibmqradar_security_information_and_event_manager
7.1.0
ibmqradar_security_information_and_event_manager
7.1.0:mr1
ibmqradar_security_information_and_event_manager
7.1.0:mr2
ibmqradar_security_information_and_event_manager
7.1.1
ibmqradar_security_information_and_event_manager
7.1.1:p1
ibmqradar_security_information_and_event_manager
7.1.1:p2
ibmqradar_security_information_and_event_manager
7.1.1:p3
ibmqradar_security_information_and_event_manager
7.1.2
ibmqradar_security_information_and_event_manager
7.1.2:p1
ibmqradar_security_information_and_event_manager
7.1.2:p10
ibmqradar_security_information_and_event_manager
7.1.2:p11
ibmqradar_security_information_and_event_manager
7.1.2:p12
ibmqradar_security_information_and_event_manager
7.1.2:p13
ibmqradar_security_information_and_event_manager
7.1.2:p2
ibmqradar_security_information_and_event_manager
7.1.2:p3
ibmqradar_security_information_and_event_manager
7.1.2:p4
ibmqradar_security_information_and_event_manager
7.1.2:p5
ibmqradar_security_information_and_event_manager
7.1.2:p6
ibmqradar_security_information_and_event_manager
7.1.2:p7
ibmqradar_security_information_and_event_manager
7.1.2:p8
ibmqradar_security_information_and_event_manager
7.1.2:p9
ibmqradar_security_information_and_event_manager
7.2
ibmqradar_security_information_and_event_manager
7.2.0
ibmqradar_security_information_and_event_manager
7.2.0:p1
ibmqradar_security_information_and_event_manager
7.2.0:p2
ibmqradar_security_information_and_event_manager
7.2.0:p3
ibmqradar_security_information_and_event_manager
7.2.1
ibmqradar_security_information_and_event_manager
7.2.1:p1
ibmqradar_security_information_and_event_manager
7.2.1:p2
ibmqradar_security_information_and_event_manager
7.2.1:p3
ibmqradar_security_information_and_event_manager
7.2.2
ibmqradar_security_information_and_event_manager
7.2.2:p1
ibmqradar_security_information_and_event_manager
7.2.2:p2
ibmqradar_security_information_and_event_manager
7.2.2:p3
ibmqradar_security_information_and_event_manager
7.2.2:p4
ibmqradar_security_information_and_event_manager
7.2.3
ibmqradar_security_information_and_event_manager
7.2.3:p1
ibmqradar_security_information_and_event_manager
7.2.3:p2
ibmqradar_security_information_and_event_manager
7.2.3:p3
ibmqradar_security_information_and_event_manager
7.2.3:p4
ibmqradar_security_information_and_event_manager
7.2.4
ibmqradar_security_information_and_event_manager
7.2.4:p1
ibmqradar_security_information_and_event_manager
7.2.4:p2
ibmqradar_security_information_and_event_manager
7.2.4:p3
ibmqradar_security_information_and_event_manager
7.2.4:p4
ibmqradar_security_information_and_event_manager
7.2.4:p5
ibmqradar_security_information_and_event_manager
7.2.4:p6
ibmqradar_security_information_and_event_manager
7.2.5
ibmqradar_security_information_and_event_manager
7.2.5:p1
ibmqradar_security_information_and_event_manager
7.2.5:p2
ibmqradar_security_information_and_event_manager
7.2.5:p3
ibmqradar_security_information_and_event_manager
7.2.5:p4
ibmqradar_security_information_and_event_manager
7.2.5:p5
ibmqradar_security_information_and_event_manager
7.2.5:p6
ibmqradar_security_information_and_event_manager
7.2.6
ibmqradar_security_information_and_event_manager
7.2.6:p1
ibmqradar_security_information_and_event_manager
7.2.6:p2
ibmqradar_security_information_and_event_manager
7.2.6:p3
ibmqradar_security_information_and_event_manager
7.2.6:p4
ibmqradar_security_information_and_event_manager
7.2.6:p5
ibmqradar_security_information_and_event_manager
7.2.6:p6
ibmqradar_security_information_and_event_manager
7.2.6:p7
ibmqradar_security_information_and_event_manager
7.2.7
ibmqradar_security_information_and_event_manager
7.2.7:p1
ibmqradar_security_information_and_event_manager
7.2.7:p2
ibmqradar_security_information_and_event_manager
7.2.7:p3
ibmqradar_security_information_and_event_manager
7.2.7:p4
ibmqradar_security_information_and_event_manager
7.2.8
ibmqradar_security_information_and_event_manager
7.2.8:p1
ibmqradar_security_information_and_event_manager
7.2.8:p10
ibmqradar_security_information_and_event_manager
7.2.8:p11
ibmqradar_security_information_and_event_manager
7.2.8:p12
ibmqradar_security_information_and_event_manager
7.2.8:p13
ibmqradar_security_information_and_event_manager
7.2.8:p14
ibmqradar_security_information_and_event_manager
7.2.8:p15
ibmqradar_security_information_and_event_manager
7.2.8:p16
ibmqradar_security_information_and_event_manager
7.2.8:p2
ibmqradar_security_information_and_event_manager
7.2.8:p3
ibmqradar_security_information_and_event_manager
7.2.8:p4
ibmqradar_security_information_and_event_manager
7.2.8:p5
ibmqradar_security_information_and_event_manager
7.2.8:p6
ibmqradar_security_information_and_event_manager
7.2.8:p7
ibmqradar_security_information_and_event_manager
7.2.8:p8
ibmqradar_security_information_and_event_manager
7.2.8:p9
ibmqradar_security_information_and_event_manager
7.2.8.15
ibmqradar_security_information_and_event_manager
7.2.9
ibmqradar_vulnerability_manager
7.2.0
ibmqradar_vulnerability_manager
7.2.1
ibmqradar_vulnerability_manager
7.2.2
ibmqradar_vulnerability_manager
7.2.3
ibmqradar_vulnerability_manager
7.2.4
ibmqradar_vulnerability_manager
7.2.6:p1
ibmqradar_vulnerability_manager
7.2.6:p2
ibmqradar_vulnerability_manager
7.2.6:p3
ibmqradar_vulnerability_manager
7.2.6:p4
ibmqradar_vulnerability_manager
7.2.6:p5
ibmqradar_vulnerability_manager
7.2.6:p6
ibmqradar_vulnerability_manager
7.2.6:p7
ibmqradar_vulnerability_manager
7.2.8
ibmqradar_vulnerability_manager
7.2.8:p1
ibmqradar_vulnerability_manager
7.2.8:p10
ibmqradar_vulnerability_manager
7.2.8:p11
ibmqradar_vulnerability_manager
7.2.8:p12
ibmqradar_vulnerability_manager
7.2.8:p13
ibmqradar_vulnerability_manager
7.2.8:p14
ibmqradar_vulnerability_manager
7.2.8:p15
ibmqradar_vulnerability_manager
7.2.8:p16
ibmqradar_vulnerability_manager
7.2.8:p17
ibmqradar_vulnerability_manager
7.2.8:p2
ibmqradar_vulnerability_manager
7.2.8:p3
ibmqradar_vulnerability_manager
7.2.8:p4
ibmqradar_vulnerability_manager
7.2.8:p5
ibmqradar_vulnerability_manager
7.2.8:p6
ibmqradar_vulnerability_manager
7.2.8:p7
ibmqradar_vulnerability_manager
7.2.8:p8
ibmqradar_vulnerability_manager
7.2.8:p9
ibmsmartcloud_entry_appliance
2.3.0
ibmsmartcloud_entry_appliance
2.4.0
ibmsmartcloud_entry_appliance
3.1.0
ibmsmartcloud_entry_appliance
3.2.0
ibmsmartcloud_provisioning
2.1.0
ibmsoftware_defined_network_for_virtual_environments
𝑥
< 1.2.1
ibmsoftware_defined_network_for_virtual_environments
𝑥
< 1.2.1
ibmsoftware_defined_network_for_virtual_environments
𝑥
< 1.2.1
ibmstarter_kit_for_cloud
2.2.0
ibmworkload_deployer
3.1.0 ≤
𝑥
≤ 3.1.0.7
ibmsecurity_access_manager_for_mobile_8.0_firmware
8.0.0.1
ibmsecurity_access_manager_for_mobile_8.0_firmware
8.0.0.2
ibmsecurity_access_manager_for_mobile_8.0_firmware
8.0.0.3
ibmsecurity_access_manager_for_mobile_8.0_firmware
8.0.0.5
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.1
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.2
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.3
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.4
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.5
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.6
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.7
ibmsecurity_access_manager_for_web_7.0_firmware
7.0.0.8
ibmsecurity_access_manager_for_web_8.0_firmware
8.0.0.2
ibmsecurity_access_manager_for_web_8.0_firmware
8.0.0.3
ibmsecurity_access_manager_for_web_8.0_firmware
8.0.0.5
ibmstorwize_v7000_firmware
1.1.0.0 ≤
𝑥
< 1.4.3.5
ibmstorwize_v7000_firmware
1.5.0.0 ≤
𝑥
< 1.5.0.4
ibmstorwize_v7000_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmstorwize_v7000_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmstorwize_v5000_firmware
1.1.0.0 ≤
𝑥
< 7.1.0.11
ibmstorwize_v5000_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmstorwize_v5000_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmstorwize_v3700_firmware
1.1.0.0 ≤
𝑥
< 7.1.0.11
ibmstorwize_v3700_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmstorwize_v3700_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmstorwize_v3500_firmware
1.1.0.0 ≤
𝑥
< 7.1.0.11
ibmstorwize_v3500_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmstorwize_v3500_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmflex_system_v7000_firmware
1.1.0.0 ≤
𝑥
< 7.1.0.11
ibmflex_system_v7000_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmflex_system_v7000_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmsan_volume_controller_firmware
1.1.0.0 ≤
𝑥
< 7.1.0.11
ibmsan_volume_controller_firmware
7.2.0.0 ≤
𝑥
< 7.2.0.9
ibmsan_volume_controller_firmware
7.3.0.0 ≤
𝑥
< 7.3.0.7
ibmstn6500_firmware
3.8.0.0 ≤
𝑥
< 3.8.0.07
ibmstn6500_firmware
3.9.1.0 ≤
𝑥
< 3.9.1.08
ibmstn6500_firmware
4.1.2.0 ≤
𝑥
< 4.1.2.06
ibmstn6800_firmware
3.8.0.0 ≤
𝑥
< 3.8.0.07
ibmstn6800_firmware
3.9.1.0 ≤
𝑥
< 3.9.1.08
ibmstn6800_firmware
4.1.2.0 ≤
𝑥
< 4.1.2.06
ibmstn7800_firmware
3.8.0.0 ≤
𝑥
< 3.8.0.07
ibmstn7800_firmware
3.9.1.0 ≤
𝑥
< 3.9.1.08
ibmstn7800_firmware
4.1.2.0 ≤
𝑥
< 4.1.2.06
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
novellzenworks_configuration_management
10.3
novellzenworks_configuration_management
11.1
novellzenworks_configuration_management
11.2
novellzenworks_configuration_management
11.3.0
novellopen_enterprise_server
2.0:sp3
novellopen_enterprise_server
11.0:sp2
checkpointsecurity_gateway
𝑥
< r77.30
f5big-ip_access_policy_manager
10.1.0 ≤
𝑥
≤ 10.2.4
f5big-ip_access_policy_manager
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_access_policy_manager
11.6.0
f5big-ip_advanced_firewall_manager
11.3.0 ≤
𝑥
≤ 11.5.1
f5big-ip_advanced_firewall_manager
11.6.0
f5big-ip_analytics
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_analytics
11.6.0
f5big-ip_application_acceleration_manager
11.4.0 ≤
𝑥
≤ 11.5.1
f5big-ip_application_acceleration_manager
11.6.0
f5big-ip_application_security_manager
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_application_security_manager
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_application_security_manager
11.6.0
f5big-ip_edge_gateway
10.1.0 ≤
𝑥
≤ 10.2.4
f5big-ip_edge_gateway
11.0.0 ≤
𝑥
≤ 11.3.0
f5big-ip_global_traffic_manager
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_global_traffic_manager
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_global_traffic_manager
11.6.0
f5big-ip_link_controller
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_link_controller
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_link_controller
11.6.0
f5big-ip_local_traffic_manager
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_local_traffic_manager
11.0.0 ≤
𝑥
≤ 11.5.1
f5big-ip_local_traffic_manager
11.6.0
f5big-ip_policy_enforcement_manager
11.3.0 ≤
𝑥
≤ 11.5.1
f5big-ip_policy_enforcement_manager
11.6.0
f5big-ip_protocol_security_module
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_protocol_security_module
11.0.0 ≤
𝑥
≤ 11.4.1
f5big-ip_wan_optimization_manager
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_wan_optimization_manager
11.0.0 ≤
𝑥
≤ 11.3.0
f5big-ip_webaccelerator
10.0.0 ≤
𝑥
≤ 10.2.4
f5big-ip_webaccelerator
11.0.0 ≤
𝑥
≤ 11.3.0
f5big-iq_cloud
4.0.0 ≤
𝑥
≤ 4.4.0
f5big-iq_device
4.2.0 ≤
𝑥
≤ 4.4.0
f5big-iq_security
4.0.0 ≤
𝑥
≤ 4.4.0
f5enterprise_manager
2.1.0 ≤
𝑥
≤ 2.3.0
f5enterprise_manager
3.0.0 ≤
𝑥
≤ 3.1.1
f5traffix_signaling_delivery_controller
4.0.0 ≤
𝑥
≤ 4.0.5
f5traffix_signaling_delivery_controller
3.3.2
f5traffix_signaling_delivery_controller
3.4.1
f5traffix_signaling_delivery_controller
3.5.1
f5traffix_signaling_delivery_controller
4.1.0
f5arx_firmware
6.0.0 ≤
𝑥
≤ 6.4.0
citrixnetscaler_sdx_firmware
𝑥
< 9.3.67.5r1
citrixnetscaler_sdx_firmware
10 ≤
𝑥
< 10.1.129.11r1
citrixnetscaler_sdx_firmware
10.5 ≤
𝑥
< 10.5.52.11r1
applemac_os_x
10.0.0 ≤
𝑥
< 10.10.0
vmwarevcenter_server_appliance
5.0
vmwarevcenter_server_appliance
5.0:update_1
vmwarevcenter_server_appliance
5.0:update_2
vmwarevcenter_server_appliance
5.1
vmwarevcenter_server_appliance
5.1:update_1
vmwarevcenter_server_appliance
5.1:update_2
vmwarevcenter_server_appliance
5.5
vmwarevcenter_server_appliance
5.5:update_1
vmwareesx
4.0
vmwareesx
4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bash
bullseye
5.1-2+deb11u1
fixed
bookworm
5.2.15-2
fixed
sid
5.2.32-1
fixed
trixie
5.2.32-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bash
trusty
Fixed 4.3-7ubuntu1.3
released
precise
Fixed 4.2-2ubuntu2.3
released
lucid
Fixed 4.1-2ubuntu3.2
released
References