CVE-2014-7169
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
CISA KEV
- Vendor
- GNU
- Product
- Bourne-Again Shell (Bash)
- Due date
- 2022-07-28
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2014-7169
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-7169
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4.3-9.2 |
| debian | bullseye | fixed | 4.3-9.2 |
| debian | forky | fixed | 4.3-9.2 |
| debian | sid | fixed | 4.3-9.2 |
| debian | trixie | fixed | 4.3-9.2 |
References
Verify integrity in audit chain (admin only). AS-IS.