CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Explotada activamente
- En el catálogo CISA de vulnerabilidades explotadas desde el 28 ene 2022
- Las agencias federales de EE. UU. deben corregirla antes del 28 jul 2022 (BOD 22-01)
- Primer ataque observado 5 días después de la divulgación
- Confirmada por sensores, no solo por informes
Apply updates per vendor instructions.
Fuente: CISA KEV · 3 oct 2026 8 sept 2026 3 sept 2026 20 ago 2026 4 jun 2026 11 mar 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProductos afectados
| Fabricantes | Producto | Versiones |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | < 4.9.12 |
| oracle | linux | 4 |
| qnap | qts | < 4.1.1 |
| mageia | mageia | 3.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0 |
| redhat | enterprise linux desktop | 5.0 |
| redhat | enterprise linux eus | 5.9 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0 |
| redhat | enterprise linux server | 5.0 |
| redhat | enterprise linux server aus | 5.6 |
| redhat | enterprise linux server from rhui | 5.0 |
| redhat | enterprise linux server tus | 6.5 |
| redhat | enterprise linux workstation | 5.0 |
| suse | studio onsite | 1.3 |
| opensuse | opensuse | 12.3 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise server | 10 |
| suse | linux enterprise software development kit | 11 |
| debian | debian linux | 7.0 |
Artículos relacionados

CISA añade fallos de ProFTPD, Struts, BIND, ONLYOFFICE y Strapi al catálogo KEV por el abuso de Flax Typhoon
CISA añade fallos de ProFTPD, Struts, BIND, ONLYOFFICE y Strapi al catálogo KEV tras la explotación atribuida a Flax Typhoon, según The Hacker News.

El FBI incauta siete dominios que daban soporte al escaneo y las operaciones de malware de Flax Typhoon
Una operación de las fuerzas del orden de Estados Unidos se ha saldado con la incautación de siete dominios que, según las acusaciones, daban soporte a
This product uses the NVD API but is not endorsed or certified by the NVD.