CVE-2014-6271
GNU Bash fino alla versione 4.3 elabora le stringhe finali che seguono le definizioni di funzione nei valori delle variabili d'ambiente, il che consente ad attaccanti remoti di eseguire codice arbitrario tramite un ambiente appositamente costruito, come dimostrato da vettori che coinvolgono la funzionalità ForceCommand di OpenSSH sshd, i moduli mod_cgi e mod_cgid di Apache HTTP Server, script eseguiti da client DHCP non specificati e altre situazioni in cui l'impostazione dell'ambiente avviene attraverso un confine di privilegi rispetto all'esecuzione di Bash, noto anche come "ShellShock." NOTA: la correzione originale per questo problema era errata; CVE-2014-7169 è stato assegnato per coprire la vulnerabilità che è ancora presente dopo la correzione errata.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 28 gen 2022
- Le agenzie federali statunitensi devono correggerla entro il 28 lug 2022 (direttiva BOD 22-01)
- Primo attacco osservato 5 giorni dopo la divulgazione
- Confermata dai sensori, non solo da segnalazioni
Apply updates per vendor instructions.
Fonte: CISA KEV · 3 ott 2026 8 set 2026 3 set 2026 20 ago 2026 4 giu 2026 11 mar 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProdotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | < 4.9.12 |
| oracle | linux | 4 |
| qnap | qts | < 4.1.1 |
| mageia | mageia | 3.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0 |
| redhat | enterprise linux desktop | 5.0 |
| redhat | enterprise linux eus | 5.9 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0 |
| redhat | enterprise linux server | 5.0 |
| redhat | enterprise linux server aus | 5.6 |
| redhat | enterprise linux server from rhui | 5.0 |
| redhat | enterprise linux server tus | 6.5 |
| redhat | enterprise linux workstation | 5.0 |
| suse | studio onsite | 1.3 |
| opensuse | opensuse | 12.3 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise server | 10 |
| suse | linux enterprise software development kit | 11 |
| debian | debian linux | 7.0 |
Articoli correlati

CISA aggiunge al KEV le falle di ProFTPD, Struts, BIND, ONLYOFFICE e Strapi per l'abuso da parte di Flax Typhoon
CISA aggiunge cinque falle di ProFTPD, Struts, BIND, ONLYOFFICE e Strapi al KEV dopo lo sfruttamento attribuito a Flax Typhoon. Dettagli e avviso.

FBI sequestra sette domini usati per le attività di scansione e malware di Flax Typhoon
FBI sequestra sette domini attribuiti a Flax Typhoon per MicroScan e FishHub per scansione, malware e accesso remoto, secondo le autorità USA.
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.