CVE-2014-6278: GNU Bash OS Command Injection Vulnerability

Published Sep 29, 2014
·
Updated

A security flaw was found in bash, which could be exploited remotely via applications which parse untrusted user scripts via bash. This flaw is different from CVE-2014-6277, CVE-2014-7169 and CVE-2014-7186.

Other sources

GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.

CISA

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and modcgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

Debian

Affected Software

30 affected componentsFixes available
GNU Bash=1.14.0
GNU Bash=1.14.1
GNU Bash=1.14.2
GNU Bash=1.14.3
GNU Bash=1.14.4
GNU Bash=1.14.5
GNU Bash=1.14.6
GNU Bash=1.14.7
GNU Bash=2.0
GNU Bash=2.01
GNU Bash=2.01.1
GNU Bash=2.02
GNU Bash=2.02.1
GNU Bash=2.03
GNU Bash=2.04
GNU Bash=2.05
GNU Bash=2.05-a
GNU Bash=2.05-b
GNU Bash=3.0
GNU Bash=3.0.16
GNU Bash=3.1
GNU Bash=3.2
GNU Bash=3.2.48
GNU Bash=4.0
GNU Bash=4.0-rc1
GNU Bash=4.1
GNU Bash=4.2
GNU Bash=4.3
GNU GNU Bash
debian/bash
5.1-2+deb11u15.2.15-25.2.37-25.3-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/bash to a version that resolves this vulnerability.

    Fixed in 5.1-2+deb11u1Fixed in 5.2.15-2Fixed in 5.2.37-2Fixed in 5.3-3
  2. Upgrade

    Upgrade debian/bash to a version that resolves this vulnerability.

    Fixed in 5.1-2+deb11u1
  3. Upgrade

    Upgrade debian/bash to a version that resolves this vulnerability.

    Fixed in 5.2.15-2
  4. Upgrade

    Upgrade debian/bash to a version that resolves this vulnerability.

    Fixed in 5.2.37-2
  5. Upgrade

    Upgrade debian/bash to a version that resolves this vulnerability.

    Fixed in 5.3-3
  6. Compensating control

    Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services; discontinue use of the product if mitigations are unavailable.

Event History

Sep 29, 2014
Data Sourced
via Red Hat·08:40 AM
DescriptionSeverityAffected Software
Sep 30, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 2, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
May 13, 2026
Data Sourced
via Debian·09:00 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2014-6278?

CVE-2014-6278 has been rated as high severity due to its potential for remote exploitation.

2

How do I fix CVE-2014-6278?

To fix CVE-2014-6278, update your bash version to 5.1-2+deb11u1 or later.

3

Which versions of bash are affected by CVE-2014-6278?

CVE-2014-6278 affects multiple versions of bash, including 1.14.0 through 4.3.

4

Can CVE-2014-6278 be exploited remotely?

Yes, CVE-2014-6278 can be exploited remotely via applications that parse untrusted user scripts.

5

Is CVE-2014-6278 related to any other vulnerabilities?

CVE-2014-6278 is a distinct vulnerability and is not the same as CVE-2014-6277.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203