TROYANOSYVIRUS
Back to CVEs

CVE-2014-6278

HIGHCISA KEV
8.8

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published9/30/2014
Last Modified4/22/2026
Sourcekev
Honeypot Sightings0

CISA KEV

VendorGNU
ProductGNU Bash
Vulnerability NameGNU Bash OS Command Injection Vulnerability
KEV Date Added2025-10-02
Remediation Due Date2025-10-23
Ransomware UseUnknown

Affected Products

gnu:bash

Weaknesses (CWE)

CWE-78CWE-78

References

http://jvn.jp/en/jp/JVN55667175/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126(af854a3a-2127-422b-91ae-364da2661108)
http://linux.oracle.com/errata/ELSA-2014-3093(af854a3a-2127-422b-91ae-364da2661108)
http://linux.oracle.com/errata/ELSA-2014-3094(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141330468527613&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141345648114150&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383026420882&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383081521087&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383196021590&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383244821813&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383304022067&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383353622268&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141383465822787&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141450491804793&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141576728022234&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141577137423233&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141577241923505&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141577297623641&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141585637922673&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141879528318582&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142118135300698&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142358026505815&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142358078406056&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142721162228379&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/58200(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59907(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59961(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60024(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60034(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60044(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60055(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60063(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60193(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60325(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60433(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61065(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61128(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61129(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61283(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61287(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61291(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61312(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61313(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61328(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61442(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61471(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61485(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61503(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61550(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61552(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61565(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61603(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61633(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61641(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61643(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61654(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61703(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61780(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61816(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61857(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/62312(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/62343(af854a3a-2127-422b-91ae-364da2661108)
http://support.novell.com/security/cve/CVE-2014-6278.html(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21685541(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21685604(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21685733(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21685749(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21685914(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686131(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686246(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686445(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686479(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686494(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21687079(af854a3a-2127-422b-91ae-364da2661108)
http://www.novell.com/support/kb/doc.php?id=7015721(af854a3a-2127-422b-91ae-364da2661108)
http://www.qnap.com/i/en/support/con_show.php?cid=61(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2380-1(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=1147414(af854a3a-2127-422b-91ae-364da2661108)
https://kb.bluecoat.com/index?page=content&id=SA82(af854a3a-2127-422b-91ae-364da2661108)
https://security-tracker.debian.org/tracker/CVE-2014-6278(af854a3a-2127-422b-91ae-364da2661108)
https://support.citrix.com/article/CTX200217(af854a3a-2127-422b-91ae-364da2661108)
https://support.citrix.com/article/CTX200223(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/39568/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/39887/(af854a3a-2127-422b-91ae-364da2661108)
https://www.suse.com/support/shellshock/(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.