Junglewise Threat Intelligence

CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

CVE-2014-7169 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Technologies: Gnu Bash. Vendors: Gnu.

Executive brief

GNU Bash through 4.3 incorrectly processes trailing strings after malformed function definitions in environment variables. This allows remote attackers to execute arbitrary code or write to files when environment variables are set across a privilege boundary, such as in OpenSSH ForceCommand or Apache mod_cgi.

Affected products

  • GNU Bash through 4.3 bash43-025

Timeline

  • 2022-01-28: disclosed: Publication date listed in advisory.
  • exploited: Reported as exploited in the wild.

Related threats