Back

CVE-2014-7169

CRITICAL CISA KEV

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Published: Sep 25, 2014 Modified: Apr 22, 2026
CWE-78 CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (334)

Vendor Product Version
gnu bash *
arista eos * ≥ 4.9.0 < 4.9.12
arista eos * ≥ 4.10.0 < 4.10.9
arista eos * ≥ 4.11.0 < 4.11.11
arista eos * ≥ 4.12.0 < 4.12.9
arista eos * ≥ 4.13.0 < 4.13.9
arista eos * ≥ 4.14.0 < 4.14.4f
oracle linux 4
oracle linux 5
oracle linux 6
qnap qts * < 4.1.1
qnap qts 4.1.1
qnap qts 4.1.1
mageia mageia 3.0
mageia mageia 4.0
redhat gluster_storage_server_for_on-premise 2.1
redhat virtualization 3.4
redhat enterprise_linux 4.0
redhat enterprise_linux 5.0
redhat enterprise_linux 6.0

…and 314 more

GitHub Security Advisory GHSA-f7j6-xrjp-vffg

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 89.06%

Top 0% most likely to be exploited

Threat Score 95.9 / 100

CISA Known Exploited

Date Added: 2022-01-28
Due Date: 2022-07-28
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub