CVE-2014-6271 - CVE House
Back to Database
Status published Unknown CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions...

Vulnerability Description

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-6271

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

bash, eos, linux, qts, mageia, gluster storage server for on-premise, virtualization, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for scientific computing, enterprise linux server, enterprise linux server aus, enterprise linux server from rhui, enterprise linux server tus, enterprise linux workstation, studio onsite, opensuse, linux enterprise desktop, linux enterprise server, linux enterprise software development kit, debian linux, infosphere guardium database activity monitoring, pureapplication system, qradar risk manager, qradar security information and event manager, qradar vulnerability manager, smartcloud entry appliance, smartcloud provisioning, software defined network for virtual environments, starter kit for cloud, workload deployer, security access manager for mobile 8.0 firmware, security access manager for web 7.0 firmware, security access manager for web 8.0 firmware, storwize v7000 firmware, storwize v5000 firmware, storwize v3700 firmware, storwize v3500 firmware, flex system v7000 firmware, san volume controller firmware, stn6500 firmware, stn6800 firmware, stn7800 firmware, ubuntu linux, zenworks configuration management, open enterprise server, security gateway, big-ip access policy manager, big-ip advanced firewall manager, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip edge gateway, big-ip global traffic manager, big-ip link controller, big-ip local traffic manager, big-ip policy enforcement manager, big-ip protocol security module, big-ip wan optimization manager, big-ip webaccelerator, big-iq cloud, big-iq device, big-iq security, enterprise manager, traffix signaling delivery controller, arx firmware, netscaler sdx firmware, mac os x, vcenter server appliance, esx
Vulnerable Versions:
0, 4.9.0, 4.10.0, 4.11.0, 4.12.0, 4.13.0, 4.14.0, 4, 5, 6, 4.1.1, 3.0, 4.0, 2.1, 3.4, 5.0, 6.0, 7.0, 5.9, 6.4, 6.5, 7.3, 7.4, 7.5, 7.6, 7.7, 5.9_s390x, 6.4_s390x, 6.5_s390x, 7.3_s390x, 7.4_s390x, 7.5_s390x, 7.6_s390x, 7.7_s390x, 5.0_ppc, 5.9_ppc, 6.0_ppc64, 6.4_ppc64, 7.0_ppc64, 6.5_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64, 5.6, 6.2, 1.3, 12.3, 13.1, 13.2, 11, 12, 10, 8.2, 9.0, 9.1, 1.0.0.0, 1.1.0.0, 2.0.0.0, 7.1.0, 7.1.1, 7.1.2, 7.2, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.8.15, 7.2.9, 2.3.0, 2.4.0, 3.1.0, 3.2.0, 2.1.0, 2.2.0, 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.5, 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.0.4, 7.0.0.5, 7.0.0.6, 7.0.0.7, 7.0.0.8, 1.5.0.0, 7.2.0.0, 7.3.0.0, 3.8.0.0, 3.9.1.0, 4.1.2.0, 10.04, 12.04, 14.04, 10.3, 11.1, 11.2, 11.3.0, 2.0, 11.0, 10.1.0, 11.0.0, 11.6.0, 11.4.0, 10.0.0, 4.0.0, 4.2.0, 3.0.0, 3.3.2, 3.4.1, 3.5.1, 4.1.0, 6.0.0, 10.5, 5.1, 5.5, 4.1

Timeline

Official Publish: September 24th, 2014
Last Modified: October 22nd, 2025
Added to House: July 19th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.