CVE-2014-6278: GNU Bash OS Command Injection Vulnerability
A security flaw was found in bash, which could be exploited remotely via applications which parse untrusted user scripts via bash. This flaw is different from CVE-2014-6277, CVE-2014-7169 and CVE-2014-7186.
Other sources
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
— CISA
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and modcgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/bashto a version that resolves this vulnerability.Fixed in 5.1-2+deb11u1Fixed in 5.2.15-2Fixed in 5.2.37-2Fixed in 5.3-3 - Upgrade
Upgrade
debian/bashto a version that resolves this vulnerability.Fixed in 5.1-2+deb11u1 - Upgrade
Upgrade
debian/bashto a version that resolves this vulnerability.Fixed in 5.2.15-2 - Upgrade
Upgrade
debian/bashto a version that resolves this vulnerability.Fixed in 5.2.37-2 - Upgrade
Upgrade
debian/bashto a version that resolves this vulnerability.Fixed in 5.3-3 - Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services; discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6278?
CVE-2014-6278 has been rated as high severity due to its potential for remote exploitation.
How do I fix CVE-2014-6278?
To fix CVE-2014-6278, update your bash version to 5.1-2+deb11u1 or later.
Which versions of bash are affected by CVE-2014-6278?
CVE-2014-6278 affects multiple versions of bash, including 1.14.0 through 4.3.
Can CVE-2014-6278 be exploited remotely?
Yes, CVE-2014-6278 can be exploited remotely via applications that parse untrusted user scripts.
Is CVE-2014-6278 related to any other vulnerabilities?
CVE-2014-6278 is a distinct vulnerability and is not the same as CVE-2014-6277.