GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
GNU Bash hasta 4.3 bash43-026 no analiza debidamente las definiciones de funciones en los valores de las variables de entornos, lo que permite a atacantes remotos ejecutar comandos arbitrarios a través de un entorno manipulado, como fue demostrado por vectores involucrando la caracteristica ForceCommand en OpenSSH sshd, los módulos mod_cgi y mod_cgid en el servidor Apache HTTP, secuencias de comandos ejecutadas por clientes DHCP no especificados, y otras situaciones en las cuales la configuración del entorno ocurre tras un límite de privilegios de la ejecución de Bash. NOTA: esta vulnerabilidad existe debido a una solución incompleta para el CVE-2014-6271, CVE-2014-7169, y CVE-2014-6277.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Type: Secondary
Exploitability Score: 2.8
Impact Score: 5.9
AV:N/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-78
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-78
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| gnu | bash | 1.14.0 | <built-in method update of dict object at 0x7e60bb328600> | Application |
| gnu | bash | 1.14.1 | <built-in method update of dict object at 0x7e60b8478340> | Application |
| gnu | bash | 1.14.2 | <built-in method update of dict object at 0x7e6112303ac0> | Application |
| gnu | bash | 1.14.3 | <built-in method update of dict object at 0x7e611238b940> | Application |
| gnu | bash | 1.14.4 | <built-in method update of dict object at 0x7e60bb328540> | Application |
| gnu | bash | 1.14.5 | <built-in method update of dict object at 0x7e60bb3298c0> | Application |
| gnu | bash | 1.14.6 | <built-in method update of dict object at 0x7e60bb32b040> | Application |
| gnu | bash | 1.14.7 | <built-in method update of dict object at 0x7e61342e7f80> | Application |
| gnu | bash | 2.0 | <built-in method update of dict object at 0x7e60bb3297c0> | Application |
| gnu | bash | 2.01 | <built-in method update of dict object at 0x7e60bb32b1c0> | Application |
| gnu | bash | 2.01.1 | <built-in method update of dict object at 0x7e60b847ab80> | Application |
| gnu | bash | 2.02 | <built-in method update of dict object at 0x7e60bb329f00> | Application |
| gnu | bash | 2.02.1 | <built-in method update of dict object at 0x7e60b8478880> | Application |
| gnu | bash | 2.03 | <built-in method update of dict object at 0x7e60bb32bf40> | Application |
| gnu | bash | 2.04 | <built-in method update of dict object at 0x7e60bb329180> | Application |
| gnu | bash | 2.05 | <built-in method update of dict object at 0x7e60b847b9c0> | Application |
| gnu | bash | 2.05 | <built-in method update of dict object at 0x7e60bb32a740> | Application |
| gnu | bash | 2.05 | <built-in method update of dict object at 0x7e61342e5f00> | Application |
| gnu | bash | 3.0 | <built-in method update of dict object at 0x7e60b8479680> | Application |
| gnu | bash | 3.0.16 | <built-in method update of dict object at 0x7e60baa0b0c0> | Application |
| gnu | bash | 3.1 | <built-in method update of dict object at 0x7e60baa0a740> | Application |
| gnu | bash | 3.2 | <built-in method update of dict object at 0x7e60bb329480> | Application |
| gnu | bash | 3.2.48 | <built-in method update of dict object at 0x7e6111c1d740> | Application |
| gnu | bash | 4.0 | <built-in method update of dict object at 0x7e60bb32b200> | Application |
| gnu | bash | 4.0 | <built-in method update of dict object at 0x7e61342e72c0> | Application |
| gnu | bash | 4.1 | <built-in method update of dict object at 0x7e60bb32bcc0> | Application |
| gnu | bash | 4.2 | <built-in method update of dict object at 0x7e61342e7b80> | Application |
| gnu | bash | 4.3 | <built-in method update of dict object at 0x7e60baa08280> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.5:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.6:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:1.14.7:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.01:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.01.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.02:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.02.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.03:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.04:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.05:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.05:a:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:2.05:b:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:3.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:3.0.16:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:3.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:3.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:3.2.48:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:4.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:4.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:4.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:4.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:gnu:bash:4.3:*:*:*:*:*:*:* |