← Vulnerability feed

Vulnerability record · CVE-2014-6277 · published 27 September 2014

CVE-2014-6277: GNU Bash environment function parsing flaw allows command execution

Gnu · Bash

GNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing crafted environments to trigger uninitialized memory access and untrusted pointer reads and writes. It is an incomplete fix for CVE-2014-6271 and CVE-2014-7169, so systems patched only for those earlier flaws remain exposed.

10.0 CVSS 2.0 High EPSS 70% · top 0.6% CWE-78 · OS command injection
10.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
218References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityNetwork-reachable, unauthenticated code execution with a very high EPSS score and public exploit references, though it is not in KEV and requires an environment-setting vector.

What it is

GNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing crafted environments to trigger uninitialized memory access and untrusted pointer reads and writes. It is an incomplete fix for CVE-2014-6271 and CVE-2014-7169, so systems patched only for those earlier flaws remain exposed.

Impact

An attacker can execute arbitrary code or cause a denial of service in the context of the process that invokes Bash across a privilege boundary.

Attack surface

Reached remotely over the network with no authentication and no user interaction (AV:N/AC:L/Au:N), through vectors such as OpenSSH ForceCommand, Apache mod_cgi/mod_cgid, DHCP client scripts, and any path where the environment is set across a privilege boundary before Bash runs.

Exploitation

Not listed in CISA KEV, but EPSS is 0.64326 (99.194th percentile), and a reference is tagged Exploit and Patch, indicating public exploit material exists.

What to do

  • Patch Bash to a version that fully addresses CVE-2014-6277 and the earlier CVE-2014-6271/CVE-2014-7169 fixes; verify the distribution's updated package rather than relying on the initial Shellshock patch.
  • Apply vendor errata for all affected platforms (Oracle ELSA-2014-3093/3094, openSUSE, Apple) and re-check any system patched only in September 2014.
  • Reduce exposure by disabling or restricting CGI on Apache where not required and limiting ForceCommand use in sshd.
  • Sanitize or strip function definitions from environment variables passed across privilege boundaries (for example via sudo, sshd, or CGI) until patching is complete.

Detection

  • Monitor for Bash processes spawned from CGI, sshd ForceCommand, or DHCP scripts with unusual environment contents or unexpected child processes.
  • Alert on outbound network connections or shell execution originating from web server and SSH service accounts.
  • Audit installed Bash package versions against vendor fixed releases and flag hosts still running pre-fix builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jvn.jp/en/jp/JVN55667175/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html ExploitPatch
http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html
http://linux.oracle.com/errata/ELSA-2014-3093
http://linux.oracle.com/errata/ELSA-2014-3094
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
http://marc.info/?l=bugtraq&m=141330468527613&w=2
http://marc.info/?l=bugtraq&m=141345648114150&w=2
http://marc.info/?l=bugtraq&m=141383026420882&w=2
http://marc.info/?l=bugtraq&m=141383081521087&w=2
http://marc.info/?l=bugtraq&m=141383196021590&w=2
http://marc.info/?l=bugtraq&m=141383244821813&w=2
http://marc.info/?l=bugtraq&m=141383304022067&w=2
http://marc.info/?l=bugtraq&m=141383353622268&w=2
http://marc.info/?l=bugtraq&m=141383465822787&w=2
http://marc.info/?l=bugtraq&m=141450491804793&w=2
http://marc.info/?l=bugtraq&m=141576728022234&w=2
http://marc.info/?l=bugtraq&m=141577137423233&w=2
http://marc.info/?l=bugtraq&m=141577241923505&w=2
http://marc.info/?l=bugtraq&m=141577297623641&w=2
http://marc.info/?l=bugtraq&m=141585637922673&w=2
http://marc.info/?l=bugtraq&m=141879528318582&w=2
http://marc.info/?l=bugtraq&m=142118135300698&w=2
http://marc.info/?l=bugtraq&m=142289270617409&w=2
http://marc.info/?l=bugtraq&m=142358026505815&w=2
http://marc.info/?l=bugtraq&m=142358078406056&w=2
http://marc.info/?l=bugtraq&m=142721162228379&w=2
http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html
http://secunia.com/advisories/58200
http://secunia.com/advisories/59907
http://secunia.com/advisories/59961
http://secunia.com/advisories/60024
http://secunia.com/advisories/60034
http://secunia.com/advisories/60044
http://secunia.com/advisories/60055
http://secunia.com/advisories/60063

Track CVE-2014-6277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed8.8CVE-2014-6278GNU Bash environment function parsing command injectionGNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing command injection when the envi…KEVEPSS 100%analysed10.0CVE-2014-7186GNU Bash redirection stack out-of-bounds access via here documentsThe redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 mishandles here documents, causing an out-of-bounds array access in the …EPSS 66%analysed10.0CVE-2014-7187GNU Bash off-by-one in read_token_word causes crashGNU Bash through 4.3 bash43-026 contains an off-by-one error in the read_token_word function in parse.y, the 'word_lineno' issue. Deeply nested for l…EPSS 65%analysed8.4CVE-2016-7543Gnu bash improper input validation vulnerabilityBash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.EPSS 0.58%7.8CVE-2022-3715Gnu bash memory buffer overflow vulnerabilityA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.EPSS 0.36%7.8CVE-2019-18276Gnu bash vulnerabilityAn issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2014-6277), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.