Executive brief
GNU Bash through 4.3 incorrectly processes trailing strings after function definitions in environment variable values. This allows remote attackers to execute arbitrary code when environment variables are set across a privilege boundary, such as in OpenSSH ForceCommand, Apache mod_cgi, or DHCP client scripts.
Affected products
- GNU Bash through 4.3
Timeline
- 2022-01-28: disclosed: Publication date of the advisory.
- exploited: Reported as exploited in the wild.