Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-6278

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.892
EPSS Ranking 99.5%
CVSS Severity
CVSS v2 Score 10.0
References
Products affected by CVE-2014-6278
  • Gnu » Bash » Version: 1.14.0
    cpe:2.3:a:gnu:bash:1.14.0
  • Gnu » Bash » Version: 1.14.1
    cpe:2.3:a:gnu:bash:1.14.1
  • Gnu » Bash » Version: 1.14.2
    cpe:2.3:a:gnu:bash:1.14.2
  • Gnu » Bash » Version: 1.14.3
    cpe:2.3:a:gnu:bash:1.14.3
  • Gnu » Bash » Version: 1.14.4
    cpe:2.3:a:gnu:bash:1.14.4
  • Gnu » Bash » Version: 1.14.5
    cpe:2.3:a:gnu:bash:1.14.5
  • Gnu » Bash » Version: 1.14.6
    cpe:2.3:a:gnu:bash:1.14.6
  • Gnu » Bash » Version: 1.14.7
    cpe:2.3:a:gnu:bash:1.14.7
  • Gnu » Bash » Version: 2.0
    cpe:2.3:a:gnu:bash:2.0
  • Gnu » Bash » Version: 2.01
    cpe:2.3:a:gnu:bash:2.01
  • Gnu » Bash » Version: 2.01.1
    cpe:2.3:a:gnu:bash:2.01.1
  • Gnu » Bash » Version: 2.02
    cpe:2.3:a:gnu:bash:2.02
  • Gnu » Bash » Version: 2.02.1
    cpe:2.3:a:gnu:bash:2.02.1
  • Gnu » Bash » Version: 2.03
    cpe:2.3:a:gnu:bash:2.03
  • Gnu » Bash » Version: 2.04
    cpe:2.3:a:gnu:bash:2.04
  • Gnu » Bash » Version: 2.05
    cpe:2.3:a:gnu:bash:2.05
  • Gnu » Bash » Version: 3.0
    cpe:2.3:a:gnu:bash:3.0
  • Gnu » Bash » Version: 3.0.16
    cpe:2.3:a:gnu:bash:3.0.16
  • Gnu » Bash » Version: 3.1
    cpe:2.3:a:gnu:bash:3.1
  • Gnu » Bash » Version: 3.2
    cpe:2.3:a:gnu:bash:3.2
  • Gnu » Bash » Version: 3.2.48
    cpe:2.3:a:gnu:bash:3.2.48
  • Gnu » Bash » Version: 4.0
    cpe:2.3:a:gnu:bash:4.0
  • Gnu » Bash » Version: 4.1
    cpe:2.3:a:gnu:bash:4.1
  • Gnu » Bash » Version: 4.2
    cpe:2.3:a:gnu:bash:4.2
  • Gnu » Bash » Version: 4.3
    cpe:2.3:a:gnu:bash:4.3


Contact Us

Shodan ® - All rights reserved