CVE-2014-6278

8.8 HIGH CISA KEV - Actively Exploited
Published: September 30, 2014 Modified: October 22, 2025

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/58200
Source: security@debian.org
http://secunia.com/advisories/59907
Source: security@debian.org
http://secunia.com/advisories/59961
Source: security@debian.org
http://secunia.com/advisories/60024
Source: security@debian.org
http://secunia.com/advisories/60034
Source: security@debian.org
http://secunia.com/advisories/60044
Source: security@debian.org
http://secunia.com/advisories/60055
Source: security@debian.org
http://secunia.com/advisories/60063
Source: security@debian.org
http://secunia.com/advisories/60193
Source: security@debian.org
http://secunia.com/advisories/60325
Source: security@debian.org
http://secunia.com/advisories/60433
Source: security@debian.org
http://secunia.com/advisories/61065
Source: security@debian.org
http://secunia.com/advisories/61128
Source: security@debian.org
http://secunia.com/advisories/61129
Source: security@debian.org
http://secunia.com/advisories/61283
Source: security@debian.org
http://secunia.com/advisories/61287
Source: security@debian.org
http://secunia.com/advisories/61291
Source: security@debian.org
http://secunia.com/advisories/61312
Source: security@debian.org
http://secunia.com/advisories/61313
Source: security@debian.org
http://secunia.com/advisories/61328
Source: security@debian.org
http://secunia.com/advisories/61442
Source: security@debian.org
http://secunia.com/advisories/61471
Source: security@debian.org
http://secunia.com/advisories/61485
Source: security@debian.org
http://secunia.com/advisories/61503
Source: security@debian.org
http://secunia.com/advisories/61550
Source: security@debian.org
http://secunia.com/advisories/61552
Source: security@debian.org
http://secunia.com/advisories/61565
Source: security@debian.org
http://secunia.com/advisories/61603
Source: security@debian.org
http://secunia.com/advisories/61633
Source: security@debian.org
http://secunia.com/advisories/61641
Source: security@debian.org
http://secunia.com/advisories/61643
Source: security@debian.org
http://secunia.com/advisories/61654
Source: security@debian.org
http://secunia.com/advisories/61703
Source: security@debian.org
http://secunia.com/advisories/61780
Source: security@debian.org
http://secunia.com/advisories/61816
Source: security@debian.org
http://secunia.com/advisories/61857
Source: security@debian.org
http://secunia.com/advisories/62312
Source: security@debian.org
http://secunia.com/advisories/62343
Source: security@debian.org
http://www.ubuntu.com/usn/USN-2380-1
Source: security@debian.org
https://www.suse.com/support/shellshock/
Source: security@debian.org
http://jvn.jp/en/jp/JVN55667175/index.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
Source: af854a3a-2127-422b-91ae-364da2661108
http://linux.oracle.com/errata/ELSA-2014-3093
Source: af854a3a-2127-422b-91ae-364da2661108
http://linux.oracle.com/errata/ELSA-2014-3094
Source: af854a3a-2127-422b-91ae-364da2661108
http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141330468527613&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141345648114150&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383026420882&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383081521087&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383196021590&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383244821813&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383304022067&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383353622268&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141383465822787&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141450491804793&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141576728022234&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141577137423233&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141577241923505&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141577297623641&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141585637922673&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141879528318582&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142118135300698&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142358026505815&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142358078406056&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142721162228379&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/58200
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59907
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59961
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60024
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60034
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60044
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60055
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60063
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60193
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60325
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60433
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61065
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61128
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61129
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61283
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61287
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61291
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61312
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61313
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61328
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61442
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61471
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61485
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61503
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61550
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61552
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61565
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61603
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61633
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61641
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61643
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61654
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61703
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61780
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61816
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/61857
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/62312
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/62343
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.novell.com/security/cve/CVE-2014-6278.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21685541
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21685733
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21685749
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21685914
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21686131
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21686246
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21686445
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21686479
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21686494
Source: af854a3a-2127-422b-91ae-364da2661108
http://www-01.ibm.com/support/docview.wss?uid=swg21687079
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2015:164
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/support/kb/doc.php?id=7015721
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.qnap.com/i/en/support/con_show.php?cid=61
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-2380-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/security/advisories/VMSA-2014-0010.html
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=1147414
Source: af854a3a-2127-422b-91ae-364da2661108
https://kb.bluecoat.com/index?page=content&id=SA82
Source: af854a3a-2127-422b-91ae-364da2661108
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648
Source: af854a3a-2127-422b-91ae-364da2661108
https://kc.mcafee.com/corporate/index?page=content&id=SB10085
Source: af854a3a-2127-422b-91ae-364da2661108
https://security-tracker.debian.org/tracker/CVE-2014-6278
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.citrix.com/article/CTX200217
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.citrix.com/article/CTX200223
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/39568/
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/39887/
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.suse.com/support/shellshock/
Source: af854a3a-2127-422b-91ae-364da2661108

221 reference(s) from NVD

Quick Stats

CVSS v3 Score
8.8 / 10.0
EPSS (Exploit Probability)
90.5%
100th percentile
Exploitation Status
Actively Exploited
Remediation due: 2025-10-23

Weaknesses (CWE)

Affected Vendors

gnu