CVE-2014-6277

Critical10.0 Published on Sep 27, 2014

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

Early warning: exploitation observed

  • Exploitation observed since Mar 1, 2018
  • Not yet in the official CISA catalogue
  • First attack observed 1250 days after disclosure

Source: VulnCheck KEV · Mar 31, 2025 Mar 1, 2018

CVSS score10.0 / 10AV:N/AC:L/Au:N/C:C/I:C/A:C
Weakness type (CWE)CWE-78
Vendorsgnu

Affected products

VendorsProductVersions
gnubash1.14.0

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database