CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Explotada activamente
- En el catálogo CISA de vulnerabilidades explotadas desde el 28 ene 2022
- Las agencias federales de EE. UU. deben corregirla antes del 28 jul 2022 (BOD 22-01)
- Primer ataque observado 5 días después de la divulgación
Apply updates per vendor instructions.
Fuente: CISA KEV · 31 mar 2025 28 ene 2022 1 mar 2018 30 sept 2014
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProductos afectados
| Fabricantes | Producto | Versiones |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | < 4.9.12 |
| oracle | linux | 4 |
| qnap | qts | < 4.1.1 |
| mageia | mageia | 3.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0 |
| redhat | enterprise linux desktop | 5.0 |
| redhat | enterprise linux eus | 5.9 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0 |
| redhat | enterprise linux server | 5.0 |
| redhat | enterprise linux server aus | 5.6 |
| redhat | enterprise linux server from rhui | 5.0 |
| redhat | enterprise linux server tus | 6.5 |
| redhat | enterprise linux workstation | 5.0 |
| suse | studio onsite | 1.3 |
| opensuse | opensuse | 12.3 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise server | 10 |
| suse | linux enterprise software development kit | 11 |
| debian | debian linux | 7.0 |
Artículos relacionados

CISA añade fallos de ProFTPD, Struts, BIND, ONLYOFFICE y Strapi al catálogo KEV por el abuso de Flax Typhoon
CISA añade fallos de ProFTPD, Struts, BIND, ONLYOFFICE y Strapi al catálogo KEV tras la explotación atribuida a Flax Typhoon, según The Hacker News.

El FBI incauta siete dominios que daban soporte al escaneo y las operaciones de malware de Flax Typhoon
Una operación de las fuerzas del orden de Estados Unidos se ha saldado con la incautación de siete dominios que, según las acusaciones, daban soporte a
This product uses the NVD API but is not endorsed or certified by the NVD.