← לוח פגיעויות

CVE-2014-7169

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-78

מוצרים מושפעים

gnu: bash; arista: eos; oracle: linux; qnap: qts; mageia: mageia; redhat: gluster storage server for on-premise; redhat: virtualization; redhat: enterprise linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for power big endian; redhat: enterprise linux for power big endian eus; redhat: enterprise linux for scientific computing; redhat: enterprise linux server

קישורים