IM
IronMonkey Threat Research

CVE-2014-7187 HIGH

Published: 2014-09-28 | Last Modified: 2026-06-17 | Status: Modified

Description

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

Additional Descriptions (1)

Error de superación de límite (off-by-one) en la función read_token_word en parse.y en GNU Bash hasta 4.3 bash43-026 permite a atacantes remotos causar una denegación de servicio (acceso a array fuera de rango y caída de la aplicación) o posiblemente tener otro impacto no especificado a través de profundamente anidados para bucles, también conocido como el problema 'word_lineno'.

CVSS Metrics

Base Score: 10.0 (HIGH)

AV:N/AC:L/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
gnu bash 1.14.0 <built-in method update of dict object at 0x7e6111c1c500> Application
gnu bash 1.14.1 <built-in method update of dict object at 0x7e6110f84040> Application
gnu bash 1.14.2 <built-in method update of dict object at 0x7e60baa0a280> Application
gnu bash 1.14.3 <built-in method update of dict object at 0x7e60e8875980> Application
gnu bash 1.14.4 <built-in method update of dict object at 0x7e60bafadbc0> Application
gnu bash 1.14.5 <built-in method update of dict object at 0x7e60bafaedc0> Application
gnu bash 1.14.6 <built-in method update of dict object at 0x7e6110f86f80> Application
gnu bash 1.14.7 <built-in method update of dict object at 0x7e6111c1e080> Application
gnu bash 2.0 <built-in method update of dict object at 0x7e6110f87040> Application
gnu bash 2.01 <built-in method update of dict object at 0x7e60bafafc40> Application
gnu bash 2.01.1 <built-in method update of dict object at 0x7e60bafaed40> Application
gnu bash 2.02 <built-in method update of dict object at 0x7e6111c1dd00> Application
gnu bash 2.02.1 <built-in method update of dict object at 0x7e611232c700> Application
gnu bash 2.03 <built-in method update of dict object at 0x7e60baa0bd40> Application
gnu bash 2.04 <built-in method update of dict object at 0x7e6111c1c9c0> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e6111c1c700> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e6111c1da40> Application
gnu bash 2.05 <built-in method update of dict object at 0x7e60e8877d00> Application
gnu bash 3.0 <built-in method update of dict object at 0x7e60e8875000> Application
gnu bash 3.0.16 <built-in method update of dict object at 0x7e60baa0ac40> Application
gnu bash 3.1 <built-in method update of dict object at 0x7e60bafad300> Application
gnu bash 3.2 <built-in method update of dict object at 0x7e6111c1f380> Application
gnu bash 3.2.48 <built-in method update of dict object at 0x7e60baa0b040> Application
gnu bash 4.0 <built-in method update of dict object at 0x7e60bafae8c0> Application
gnu bash 4.0 <built-in method update of dict object at 0x7e60baa08280> Application
gnu bash 4.1 <built-in method update of dict object at 0x7e6110f846c0> Application
gnu bash 4.2 <built-in method update of dict object at 0x7e60e8874e00> Application
gnu bash 4.3 <built-in method update of dict object at 0x7e6110f86940> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:1.14.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.01:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.01.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.02:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.02.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.03:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.04:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:a:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:2.05:b:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.0.16:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:3.2.48:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:gnu:bash:4.3:*:*:*:*:*:*:*

References

Notification
Message here