CVE-2014-6271 Detail Modified This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided. Current Description GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

View Analysis Description Analysis Description GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix. Severity CVSS Version 3.x CVSS Version 2.0



CVSS 3.x Severity and Metrics:

NIST: NVD Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS 2.0 Severity and Metrics:



NIST: NVD Base Score: 10.0 HIGH Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C) Weakness Enumeration CWE-ID CWE Name Source CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') NIST Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Denotes Vulnerable Software

Are we missing a CPE here? Please let us know.

Change History 27 change records found show changes Modified Analysis 9/27/2019 1:37:27 PM Action Type Old Value New Value Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H



Changed Reference Type http://advisories.mageia.org/MGASA-2014-0388.html No Types Assigned



http://advisories.mageia.org/MGASA-2014-0388.html Third Party Advisory



Changed Reference Type http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html No Types Assigned



http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html Third Party Advisory



Changed Reference Type http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 Vendor Advisory



http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 Third Party Advisory, VDB Entry, Vendor Advisory



Changed Reference Type http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 No Types Assigned



http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 Third Party Advisory



Changed Reference Type http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html No Types Assigned



http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html Third Party Advisory



Changed Reference Type http://linux.oracle.com/errata/ELSA-2014-1293.html No Types Assigned



http://linux.oracle.com/errata/ELSA-2014-1293.html Third Party Advisory



Changed Reference Type http://linux.oracle.com/errata/ELSA-2014-1294.html No Types Assigned



http://linux.oracle.com/errata/ELSA-2014-1294.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00034.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00034.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00040.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00040.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00049.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00049.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html No Types Assigned



http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html No Types Assigned



http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html Third Party Advisory



Changed Reference Type http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html No Types Assigned



http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141216207813411&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141216207813411&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141216668515282&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141216668515282&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141235957116749&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141235957116749&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141319209015420&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141319209015420&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141330425327438&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141330425327438&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141330468527613&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141330468527613&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141345648114150&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141345648114150&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383026420882&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383026420882&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383081521087&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383081521087&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383138121313&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383138121313&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383196021590&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383196021590&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383244821813&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383244821813&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383304022067&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383304022067&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383353622268&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383353622268&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141383465822787&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141383465822787&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141450491804793&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141450491804793&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141576728022234&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141576728022234&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141577137423233&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141577137423233&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141577241923505&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141577241923505&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141577297623641&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141577297623641&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141585637922673&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141585637922673&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141694386919794&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141694386919794&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=141879528318582&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=141879528318582&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142113462216480&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142113462216480&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142118135300698&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142118135300698&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142358026505815&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142358026505815&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142358078406056&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142358078406056&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142546741516006&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142546741516006&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142719845423222&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142719845423222&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142721162228379&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142721162228379&w=2 Third Party Advisory



Changed Reference Type http://marc.info/?l=bugtraq&m=142805027510172&w=2 No Types Assigned



http://marc.info/?l=bugtraq&m=142805027510172&w=2 Third Party Advisory



Changed Reference Type http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html No Types Assigned



http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html Third Party Advisory, VDB Entry



Changed Reference Type http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html No Types Assigned



http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html Third Party Advisory, VDB Entry



Changed Reference Type http://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.html No Types Assigned



http://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.html Third Party Advisory, VDB Entry



Changed Reference Type http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html Exploit



http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html Exploit, Third Party Advisory, VDB Entry



Changed Reference Type http://rhn.redhat.com/errata/RHSA-2014-1293.html No Types Assigned



http://rhn.redhat.com/errata/RHSA-2014-1293.html Third Party Advisory



Changed Reference Type http://rhn.redhat.com/errata/RHSA-2014-1294.html No Types Assigned



http://rhn.redhat.com/errata/RHSA-2014-1294.html Third Party Advisory



Changed Reference Type http://rhn.redhat.com/errata/RHSA-2014-1295.html No Types Assigned



http://rhn.redhat.com/errata/RHSA-2014-1295.html Third Party Advisory



Changed Reference Type http://rhn.redhat.com/errata/RHSA-2014-1354.html No Types Assigned



http://rhn.redhat.com/errata/RHSA-2014-1354.html Third Party Advisory



Changed Reference Type http://seclists.org/fulldisclosure/2014/Oct/0 No Types Assigned



http://seclists.org/fulldisclosure/2014/Oct/0 Mailing List, Third Party Advisory



Changed Reference Type http://secunia.com/advisories/58200 No Types Assigned



http://secunia.com/advisories/58200 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/59272 No Types Assigned



http://secunia.com/advisories/59272 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/59737 No Types Assigned



http://secunia.com/advisories/59737 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/59907 No Types Assigned



http://secunia.com/advisories/59907 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60024 No Types Assigned



http://secunia.com/advisories/60024 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60034 No Types Assigned



http://secunia.com/advisories/60034 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60044 No Types Assigned



http://secunia.com/advisories/60044 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60055 No Types Assigned



http://secunia.com/advisories/60055 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60063 No Types Assigned



http://secunia.com/advisories/60063 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60193 No Types Assigned



http://secunia.com/advisories/60193 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60325 No Types Assigned



http://secunia.com/advisories/60325 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60433 No Types Assigned



http://secunia.com/advisories/60433 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/60947 No Types Assigned



http://secunia.com/advisories/60947 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61065 No Types Assigned



http://secunia.com/advisories/61065 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61128 No Types Assigned



http://secunia.com/advisories/61128 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61129 No Types Assigned



http://secunia.com/advisories/61129 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61188 No Types Assigned



http://secunia.com/advisories/61188 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61283 No Types Assigned



http://secunia.com/advisories/61283 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61287 No Types Assigned



http://secunia.com/advisories/61287 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61291 No Types Assigned



http://secunia.com/advisories/61291 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61312 No Types Assigned



http://secunia.com/advisories/61312 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61313 No Types Assigned



http://secunia.com/advisories/61313 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61328 No Types Assigned



http://secunia.com/advisories/61328 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61442 No Types Assigned



http://secunia.com/advisories/61442 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61471 No Types Assigned



http://secunia.com/advisories/61471 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61485 No Types Assigned



http://secunia.com/advisories/61485 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61503 No Types Assigned



http://secunia.com/advisories/61503 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61542 No Types Assigned



http://secunia.com/advisories/61542 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61547 No Types Assigned



http://secunia.com/advisories/61547 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61550 No Types Assigned



http://secunia.com/advisories/61550 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61552 No Types Assigned



http://secunia.com/advisories/61552 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61565 No Types Assigned



http://secunia.com/advisories/61565 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61603 No Types Assigned



http://secunia.com/advisories/61603 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61633 No Types Assigned



http://secunia.com/advisories/61633 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61641 No Types Assigned



http://secunia.com/advisories/61641 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61643 No Types Assigned



http://secunia.com/advisories/61643 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61654 No Types Assigned



http://secunia.com/advisories/61654 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61676 No Types Assigned



http://secunia.com/advisories/61676 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61700 No Types Assigned



http://secunia.com/advisories/61700 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61703 No Types Assigned



http://secunia.com/advisories/61703 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61711 No Types Assigned



http://secunia.com/advisories/61711 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61715 No Types Assigned



http://secunia.com/advisories/61715 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61780 No Types Assigned



http://secunia.com/advisories/61780 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61816 No Types Assigned



http://secunia.com/advisories/61816 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61855 No Types Assigned



http://secunia.com/advisories/61855 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61857 No Types Assigned



http://secunia.com/advisories/61857 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/61873 No Types Assigned



http://secunia.com/advisories/61873 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/62228 No Types Assigned



http://secunia.com/advisories/62228 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/62312 No Types Assigned



http://secunia.com/advisories/62312 Third Party Advisory



Changed Reference Type http://secunia.com/advisories/62343 No Types Assigned



http://secunia.com/advisories/62343 Third Party Advisory



Changed Reference Type http://support.apple.com/kb/HT6495 No Types Assigned



http://support.apple.com/kb/HT6495 Third Party Advisory



Changed Reference Type http://support.novell.com/security/cve/CVE-2014-6271.html No Types Assigned



http://support.novell.com/security/cve/CVE-2014-6271.html Third Party Advisory



Changed Reference Type http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash No Types Assigned



http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21685541 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21685541 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21685604 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21685604 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21685733 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21685733 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21685749 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21685749 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21685914 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21685914 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686084 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686084 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686131 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686131 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686246 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686246 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686445 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686445 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686447 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686447 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686479 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686479 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21686494 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21686494 Third Party Advisory



Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21687079 No Types Assigned



http://www-01.ibm.com/support/docview.wss?uid=swg21687079 Third Party Advisory



Changed Reference Type http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 No Types Assigned



http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 Third Party Advisory



Changed Reference Type http://www.debian.org/security/2014/dsa-3032 No Types Assigned



http://www.debian.org/security/2014/dsa-3032 Third Party Advisory



Changed Reference Type http://www.kb.cert.org/vuls/id/252743 US Government Resource



http://www.kb.cert.org/vuls/id/252743 Third Party Advisory, US Government Resource



Changed Reference Type http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 No Types Assigned



http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 Third Party Advisory



Changed Reference Type http://www.novell.com/support/kb/doc.php?id=7015701 No Types Assigned



http://www.novell.com/support/kb/doc.php?id=7015701 Third Party Advisory



Changed Reference Type http://www.novell.com/support/kb/doc.php?id=7015721 No Types Assigned



http://www.novell.com/support/kb/doc.php?id=7015721 Third Party Advisory



Changed Reference Type http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html No Types Assigned



http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html Third Party Advisory



Changed Reference Type http://www.qnap.com/i/en/support/con_show.php?cid=61 No Types Assigned



http://www.qnap.com/i/en/support/con_show.php?cid=61 Third Party Advisory



Changed Reference Type http://www.securityfocus.com/archive/1/533593/100/0/threaded No Types Assigned



http://www.securityfocus.com/archive/1/533593/100/0/threaded Third Party Advisory, VDB Entry



Changed Reference Type http://www.securityfocus.com/bid/70103 No Types Assigned



http://www.securityfocus.com/bid/70103 Third Party Advisory, VDB Entry



Changed Reference Type http://www.ubuntu.com/usn/USN-2362-1 No Types Assigned



http://www.ubuntu.com/usn/USN-2362-1 Third Party Advisory



Changed Reference Type http://www.us-cert.gov/ncas/alerts/TA14-268A US Government Resource



http://www.us-cert.gov/ncas/alerts/TA14-268A Third Party Advisory, US Government Resource



Changed Reference Type http://www.vmware.com/security/advisories/VMSA-2014-0010.html No Types Assigned



http://www.vmware.com/security/advisories/VMSA-2014-0010.html Third Party Advisory



Changed Reference Type http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 No Types Assigned



http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 Third Party Advisory



Changed Reference Type https://access.redhat.com/articles/1200223 No Types Assigned



https://access.redhat.com/articles/1200223 Third Party Advisory



Changed Reference Type https://access.redhat.com/node/1200223 No Types Assigned



https://access.redhat.com/node/1200223 Third Party Advisory



Changed Reference Type https://bugzilla.redhat.com/show_bug.cgi?id=1141597 Patch



https://bugzilla.redhat.com/show_bug.cgi?id=1141597 Issue Tracking, Patch, Third Party Advisory



Changed Reference Type https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes No Types Assigned



https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes Third Party Advisory



Changed Reference Type https://kb.bluecoat.com/index?page=content&id=SA82 No Types Assigned



https://kb.bluecoat.com/index?page=content&id=SA82 Third Party Advisory



Changed Reference Type https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 No Types Assigned



https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 Third Party Advisory



Changed Reference Type https://kc.mcafee.com/corporate/index?page=content&id=SB10085 No Types Assigned



https://kc.mcafee.com/corporate/index?page=content&id=SB10085 Third Party Advisory



Changed Reference Type https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/ Exploit



https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/ Exploit, Third Party Advisory



Changed Reference Type https://support.apple.com/kb/HT6535 No Types Assigned



https://support.apple.com/kb/HT6535 Third Party Advisory



Changed Reference Type https://support.citrix.com/article/CTX200217 No Types Assigned



https://support.citrix.com/article/CTX200217 Third Party Advisory



Changed Reference Type https://support.citrix.com/article/CTX200223 No Types Assigned



https://support.citrix.com/article/CTX200223 Third Party Advisory



Changed Reference Type https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html No Types Assigned



https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html Third Party Advisory



Changed Reference Type https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 No Types Assigned



https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 Third Party Advisory



Changed Reference Type https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 No Types Assigned



https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 Third Party Advisory



Changed Reference Type https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts No Types Assigned



https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts Third Party Advisory



Changed Reference Type https://www.exploit-db.com/exploits/34879/ No Types Assigned



https://www.exploit-db.com/exploits/34879/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/37816/ No Types Assigned



https://www.exploit-db.com/exploits/37816/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/38849/ No Types Assigned



https://www.exploit-db.com/exploits/38849/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/39918/ Exploit



https://www.exploit-db.com/exploits/39918/ Exploit, Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/40619/ No Types Assigned



https://www.exploit-db.com/exploits/40619/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/40938/ No Types Assigned



https://www.exploit-db.com/exploits/40938/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.exploit-db.com/exploits/42938/ No Types Assigned



https://www.exploit-db.com/exploits/42938/ Third Party Advisory, VDB Entry



Changed Reference Type https://www.suse.com/support/shellshock/ No Types Assigned



https://www.suse.com/support/shellshock/ Third Party Advisory



CVE Modified by MITRE 11/30/2018 4:29:07 PM Action Type Old Value New Value Added Reference https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes [No Types Assigned]



CVE Modified by MITRE 10/09/2018 3:50:24 PM Action Type Old Value New Value Added Reference http://www.securityfocus.com/archive/1/533593/100/0/threaded [No Types Assigned]



Removed Reference http://www.securityfocus.com/archive/1/archive/1/533593/100/0/threaded [No Types Assigned]



CVE Modified by MITRE 8/08/2018 9:29:01 PM Action Type Old Value New Value Added Reference https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 [No Types Assigned]



Added Reference https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 [No Types Assigned]



CVE Modified by MITRE 10/04/2017 9:29:02 PM Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/34879/ [No Types Assigned]



Added Reference https://www.exploit-db.com/exploits/42938/ [No Types Assigned]



CVE Modified by MITRE 9/16/2017 9:29:00 PM Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/37816/ [No Types Assigned]



CVE Modified by MITRE 9/12/2017 9:29:00 PM Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/38849/ [No Types Assigned]



CVE Modified by MITRE 9/02/2017 9:29:01 PM Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/40619/ [No Types Assigned]



Added Reference https://www.exploit-db.com/exploits/40938/ [No Types Assigned]



CVE Modified by MITRE 1/06/2017 10:0:28 PM Action Type Old Value New Value Added Reference http://linux.oracle.com/errata/ELSA-2014-1293.html [No Types Assigned]



Added Reference http://linux.oracle.com/errata/ELSA-2014-1294.html [No Types Assigned]



Added Reference http://secunia.com/advisories/59272 [No Types Assigned]



Added Reference http://secunia.com/advisories/61542 [No Types Assigned]



Added Reference http://secunia.com/advisories/61547 [No Types Assigned]



Added Reference https://access.redhat.com/node/1200223 [No Types Assigned]



CVE Modified by MITRE 1/02/2017 9:59:07 PM Action Type Old Value New Value Added Reference http://secunia.com/advisories/62228 [No Types Assigned]



Added Reference https://kc.mcafee.com/corporate/index?page=content&id=SB10085 [No Types Assigned]



CVE Modified by MITRE 12/07/2016 10:6:05 PM Action Type Old Value New Value Added Reference http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 [No Types Assigned]



CVE Modified by MITRE 11/28/2016 2:12:46 PM Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/70103 [No Types Assigned]



Modified Analysis 6/28/2016 6:44:57 AM Action Type Old Value New Value Changed Reference Type http://jvn.jp/en/jp/JVN55667175/index.html No Types Assigned



http://jvn.jp/en/jp/JVN55667175/index.html Advisory



Changed Reference Type http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 No Types Assigned



http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 Advisory



Changed Reference Type http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html No Types Assigned



http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html Exploit



Changed Reference Type https://www.exploit-db.com/exploits/39918/ No Types Assigned



https://www.exploit-db.com/exploits/39918/ Exploit



CVE Modified by Source 6/20/2016 9:59:01 PM Action Type Old Value New Value Added Reference http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html



CVE Translated 6/17/2016 7:45:02 AM Action Type Old Value New Value Added Translation Record truncated, showing 500 of 789 characters.

View Entire Change Record

GNU Bash hasta la versión 4.3 procesa cadenas finales después de las definiciones de funciones en los valores de variables de entorno, lo que permite a atacantes remotos ejecutar código arbitrario a través de un entorno manipulado, tal como se ha demostrado por vectores que involucran la característica ForceCommand en sshd OpenSSH, los módulos mod_cgi y mod_cgid en el Apache HTTP Server, scripts ejecutados por clientes DHCP no especificados, y otras situaciones en las cuales el ajuste de entorno Removed Translation Record truncated, showing 500 of 553 characters.

View Entire Change Record

GNU Bash hasta 4.3 procesa cadenas finales después de la definición de funciones en los valores de variables de entorno, lo que permite a atacantes remotos ejecutar código arbitrario a través de un entorno manipulado, tal y como se ha demostrado por vectores que involucran la característica ForceCommand en sshd OpenSSH, los módulos mod_cgi y mod_cgid en el Apache HTTP Server, scripts ejecutados por clientes DHCP no especificados, y otras situaciones en la cual establecer el entorno ocurre a trav CVE Modified by Source 6/16/2016 10:0:15 PM Action Type Old Value New Value Added Reference https://www.exploit-db.com/exploits/39918/



CVE Modified by Source 5/11/2015 10:1:44 PM Action Type Old Value New Value Added Reference http://advisories.mageia.org/MGASA-2014-0388.html



Added Reference http://www.mandriva.com/security/advisories?name=MDVSA-2015:164



Added Reference https://access.redhat.com/articles/1200223



CVE Modified by Source 4/09/2015 9:59:33 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=142805027510172&w=2



CVE Modified by Source 3/30/2015 9:59:19 PM Action Type Old Value New Value Added Reference http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0



CVE Modified by Source 3/26/2015 9:59:29 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=142719845423222&w=2



Added Reference http://marc.info/?l=bugtraq&m=142721162228379&w=2



CVE Modified by Source 3/17/2015 10:1:59 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=142118135300698&w=2



CVE Modified by Source 3/11/2015 10:0:04 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=141879528318582&w=2



Added Reference http://marc.info/?l=bugtraq&m=142113462216480&w=2



Added Reference http://marc.info/?l=bugtraq&m=142358026505815&w=2



Added Reference http://marc.info/?l=bugtraq&m=142358078406056&w=2



Added Reference http://marc.info/?l=bugtraq&m=142546741516006&w=2



CVE Modified by Source 12/23/2014 10:0:22 PM Action Type Old Value New Value Added Reference http://secunia.com/advisories/62312



Added Reference http://secunia.com/advisories/62343



CVE Modified by Source 12/02/2014 10:1:38 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=141694386919794&w=2



CVE Modified by Source 11/19/2014 9:59:28 PM Action Type Old Value New Value Added Reference http://marc.info/?l=bugtraq&m=141576728022234&w=2



Added Reference http://marc.info/?l=bugtraq&m=141577137423233&w=2



Added Reference http://marc.info/?l=bugtraq&m=141577241923505&w=2



Added Reference http://marc.info/?l=bugtraq&m=141577297623641&w=2



Added Reference http://marc.info/?l=bugtraq&m=141585637922673&w=2



CVE Modified by Source 11/13/2014 10:7:19 PM Action Type Old Value New Value Added Reference http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.html



Added Reference http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.html



Added Reference http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html



Added Reference http://marc.info/?l=bugtraq&m=141383465822787&w=2



Added Reference http://rhn.redhat.com/errata/RHSA-2014-1354.html



Added Reference http://secunia.com/advisories/61873



Added Reference http://www-01.ibm.com/support/docview.wss?uid=swg21686447



Initial CVE Analysis 9/24/2014 2:55:17 PM Action Type Old Value New Value Quick Info CVE Dictionary Entry:

CVE-2014-6271

NVD Published Date:

09/24/2014

NVD Last Modified:

10/09/2019

Source:

MITRE

