IM
IronMonkey Threat Research

CVE-2014-6277 HIGH

Published: 2014-09-27 | Last Modified: 2026-06-17 | Status: Modified

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

Additional Descriptions (1)

GNU Bash hasta 4.3 bash43-026 no analiza debidamente las definiciones de funciones en los valores de las variables de entornos, lo que permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (acceso a memoria no inicializada, y operaciones de leer y escribir de puntero no confiables) a través de un entorno manipulado, como fue demostrado por vectores que involucran la característica ForceCommand en OpenSSH sshd, los módulos mod_cgi y mod_cgid en el servidor de Apache HTTP , secuencias de comandos ejecutados por clientes DHCP no especificados, y otras situaciones en que la configuración del entorno ocurre cruzando un límite de privilegios de la ejecución de Bash. NOTA: esta vulnerabilidad existe debido a una solución incompleta para CVE-2014-6271 y CVE-2014-7169.

CVSS Metrics

Base Score: 10.0 (HIGH)

AV:N/AC:L/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-78

Affected Products

Vendor Product Version Update Type
gnu bash 1.14.0 <built-in method update of dict object at 0x7e610746b480> Application
gnu bash 1.14.1 <built-in method update of dict object at 0x7e60a8a68900> Application
gnu bash 1.14.2 <built-in method update of dict object at 0x7e60a8a6ad80> Application
gnu bash 1.14.3 <built-in method update of dict object at 0x7e60eb2d86c0> Application
gnu bash 1.14.4 <built-in method update of dict object at 0x7e61074686c0> Application
gnu bash 1.14.5 <built-in method update of dict object at 0x7e610746a100> Application
gnu bash 1.14.6 <built-in method update of dict object at 0x7e60a8a6bac0> Application
gnu bash 1.14.7 <built-in method update of dict object at 0x7e60a8a6bf40> Application
gnu bash 2.0 <built-in method update of dict object at 0x7e60a8a6bf00> Application
gnu bash 2.01 <built-in method update of dict object at 0x7e610746a2c0> Application
gnu bash 2.01.1 <built-in method update of dict object at 0x7e60a8a69380> Application
gnu bash 2.02 <built-in method update of dict object at 0x7e60a8a68c00> Application
gnu bash 2.02.1 <built-in method update of dict object at 0x7e60baa0a280> Application
gnu bash 2.03 <built-in method update of dict object at 0x7e60a8a69b80> Application
gnu bash 2.04 <built-in method update of dict object at 0x7e60a8a68d80> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e60baa09700> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e60e88750c0> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e60a8a6a040> Application
gnu bash 3.0 <built-in method update of dict object at 0x7e60a8a6b8c0> Application
gnu bash 3.0.16 <built-in method update of dict object at 0x7e60eb2d91c0> Application
gnu bash 3.1 <built-in method update of dict object at 0x7e60baa0a740> Application
gnu bash 3.2 <built-in method update of dict object at 0x7e60a8a6b540> Application
gnu bash 3.2.48 <built-in method update of dict object at 0x7e60a8a68300> Application
gnu bash 4.0 <built-in method update of dict object at 0x7e60a8a693c0> Application
gnu bash 4.0 <built-in method update of dict object at 0x7e60a8a6b280> Application
gnu bash 4.1 <built-in method update of dict object at 0x7e60baa0b240> Application
gnu bash 4.2 <built-in method update of dict object at 0x7e60e8874400> Application
gnu bash 4.3 <built-in method update of dict object at 0x7e60a8a68780> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.01:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.01.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.02:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.02.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.03:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.04:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:a:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:b:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.0.16:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.2.48:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.3:*:*:*:*:*:*:*

References

Notification
Message here