Junglewise Threat Intelligence

CVE-2014-6271: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

CVE-2014-6271 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Technologies: Gnu Bash. Vendors: Gnu.

Executive brief

GNU Bash through 4.3 incorrectly processes trailing strings after function definitions in environment variable values. This allows remote attackers to execute arbitrary code when environment variables are set across a privilege boundary, such as in OpenSSH ForceCommand, Apache mod_cgi, or DHCP client scripts.

Affected products

  • GNU Bash through 4.3

Timeline

  • 2022-01-28: disclosed: Publication date of the advisory.
  • exploited: Reported as exploited in the wild.

Related threats