Exploited
CWE
78
Advisory Published
Updated

CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

First published: Thu Sep 25 2014(Updated: )

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Credit: cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
GNU Bash
GNU Bash=1.14.0
GNU Bash=1.14.1
GNU Bash=1.14.2
GNU Bash=1.14.3
GNU Bash=1.14.4
GNU Bash=1.14.5
GNU Bash=1.14.6
GNU Bash=1.14.7
GNU Bash=2.0
GNU Bash=2.01
GNU Bash=2.01.1
GNU Bash=2.02
GNU Bash=2.02.1
GNU Bash=2.03
GNU Bash=2.04
GNU Bash=2.05
GNU Bash=2.05-a
GNU Bash=2.05-b
GNU Bash=3.0
GNU Bash=3.0.16
GNU Bash=3.1
GNU Bash=3.2
GNU Bash=3.2.48
GNU Bash=4.0
GNU Bash=4.0-rc1
GNU Bash=4.1
GNU Bash=4.2
GNU Bash=4.3
GNU Bash<=4.3
Arista EOS>=4.9.0<4.9.12
Arista EOS>=4.10.0<4.10.9
Arista EOS>=4.11.0<4.11.11
Arista EOS>=4.12.0<4.12.9
Arista EOS>=4.13.0<4.13.9
Arista EOS>=4.14.0<4.14.4f
Oracle Linux=4
Oracle Linux=5
Oracle Linux=6
QNAP QTS<4.1.1
QNAP QTS=4.1.1
QNAP QTS=4.1.1-build_0927
Mageia=3.0
Mageia=4.0
Red Hat Gluster Storage Server=2.1
Red Hat Enterprise Virtualization=3.4
Red Hat Enterprise Linux=4.0
Red Hat Enterprise Linux=5.0
Red Hat Enterprise Linux=6.0
Red Hat Enterprise Linux=7.0
Red Hat Enterprise Linux Desktop=5.0
Red Hat Enterprise Linux Desktop=6.0
Red Hat Enterprise Linux Desktop=7.0
Red Hat Enterprise Linux Server EUS=5.9
Red Hat Enterprise Linux Server EUS=6.4
Red Hat Enterprise Linux Server EUS=6.5
Red Hat Enterprise Linux Server EUS=7.3
Red Hat Enterprise Linux Server EUS=7.4
Red Hat Enterprise Linux Server EUS=7.5
Red Hat Enterprise Linux Server EUS=7.6
Red Hat Enterprise Linux Server EUS=7.7
Red Hat Enterprise Linux for IBM Z Systems=5.9_s390x
Red Hat Enterprise Linux for IBM Z Systems=6.4_s390x
Red Hat Enterprise Linux for IBM Z Systems=6.5_s390x
Red Hat Enterprise Linux for IBM Z Systems=7.3_s390x
Red Hat Enterprise Linux for IBM Z Systems=7.4_s390x
Red Hat Enterprise Linux for IBM Z Systems=7.5_s390x
Red Hat Enterprise Linux for IBM Z Systems=7.6_s390x
Red Hat Enterprise Linux for IBM Z Systems=7.7_s390x
Red Hat Enterprise Linux for Power, big endian=5.0_ppc
Red Hat Enterprise Linux for Power, big endian=5.9_ppc
Red Hat Enterprise Linux for Power, big endian=6.0_ppc64
Red Hat Enterprise Linux for Power, big endian=6.4_ppc64
Red Hat Enterprise Linux for Power, big endian=7.0_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=6.5_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=7.3_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=7.4_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=7.5_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=7.6_ppc64
Red Hat Enterprise Linux for Power, Big Endian EUS=7.7_ppc64
Red Hat Enterprise Linux for Scientific Computing=6.0
Red Hat Enterprise Linux for Scientific Computing=7.0
Red Hat Enterprise Linux Server=5.0
Red Hat Enterprise Linux Server=6.0
Red Hat Enterprise Linux Server=7.0
Red Hat Enterprise Linux Server=5.6
Red Hat Enterprise Linux Server=5.9
Red Hat Enterprise Linux Server=6.2
Red Hat Enterprise Linux Server=6.4
Red Hat Enterprise Linux Server=6.5
Red Hat Enterprise Linux Server=7.3
Red Hat Enterprise Linux Server=7.4
Red Hat Enterprise Linux Server=7.6
Red Hat Enterprise Linux Server=7.7
Red Hat Enterprise Linux Server Supplementary EUS=5.0
Red Hat Enterprise Linux Server Supplementary EUS=6.0
Red Hat Enterprise Linux Server Supplementary EUS=7.0
Red Hat Enterprise Linux Server=6.5
Red Hat Enterprise Linux Server=7.3
Red Hat Enterprise Linux Server=7.6
Red Hat Enterprise Linux Server=7.7
Red Hat Enterprise Linux Workstation=5.0
Red Hat Enterprise Linux Workstation=6.0
Red Hat Enterprise Linux Workstation=7.0
SUSE Studio Onsite Appliance=1.3
openSUSE libeconf=12.3
openSUSE libeconf=13.1
openSUSE libeconf=13.2
SUSE Linux Enterprise Desktop=11-sp3
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=10-sp3
SUSE Linux Enterprise Server=10-sp4
SUSE Linux Enterprise Server=11-sp1
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Software Development Kit=11-sp3
SUSE Linux Enterprise Software Development Kit=12
Debian=7.0
IBM InfoSphere Guardium Activity Monitor=8.2
IBM InfoSphere Guardium Activity Monitor=9.0
IBM InfoSphere Guardium Activity Monitor=9.1
IBM PureApplication System>=1.0.0.0<=1.0.0.4
IBM PureApplication System>=1.1.0.0<=1.1.0.4
IBM PureApplication System=2.0.0.0
IBM QRadar Risk Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.1.0-mr1
IBM QRadar Security Information and Event Manager=7.1.0-mr2
IBM QRadar Security Information and Event Manager=7.1.1
IBM QRadar Security Information and Event Manager=7.1.1-p1
IBM QRadar Security Information and Event Manager=7.1.1-p2
IBM QRadar Security Information and Event Manager=7.1.1-p3
IBM QRadar Security Information and Event Manager=7.1.2
IBM QRadar Security Information and Event Manager=7.1.2-p1
IBM QRadar Security Information and Event Manager=7.1.2-p10
IBM QRadar Security Information and Event Manager=7.1.2-p11
IBM QRadar Security Information and Event Manager=7.1.2-p12
IBM QRadar Security Information and Event Manager=7.1.2-p13
IBM QRadar Security Information and Event Manager=7.1.2-p2
IBM QRadar Security Information and Event Manager=7.1.2-p3
IBM QRadar Security Information and Event Manager=7.1.2-p4
IBM QRadar Security Information and Event Manager=7.1.2-p5
IBM QRadar Security Information and Event Manager=7.1.2-p6
IBM QRadar Security Information and Event Manager=7.1.2-p7
IBM QRadar Security Information and Event Manager=7.1.2-p8
IBM QRadar Security Information and Event Manager=7.1.2-p9
IBM QRadar Security Information and Event Manager=7.2
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.0-p1
IBM QRadar Security Information and Event Manager=7.2.0-p2
IBM QRadar Security Information and Event Manager=7.2.0-p3
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.1-p1
IBM QRadar Security Information and Event Manager=7.2.1-p2
IBM QRadar Security Information and Event Manager=7.2.1-p3
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.2-p1
IBM QRadar Security Information and Event Manager=7.2.2-p2
IBM QRadar Security Information and Event Manager=7.2.2-p3
IBM QRadar Security Information and Event Manager=7.2.2-p4
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.3-p1
IBM QRadar Security Information and Event Manager=7.2.3-p2
IBM QRadar Security Information and Event Manager=7.2.3-p3
IBM QRadar Security Information and Event Manager=7.2.3-p4
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.4-p1
IBM QRadar Security Information and Event Manager=7.2.4-p2
IBM QRadar Security Information and Event Manager=7.2.4-p3
IBM QRadar Security Information and Event Manager=7.2.4-p4
IBM QRadar Security Information and Event Manager=7.2.4-p5
IBM QRadar Security Information and Event Manager=7.2.4-p6
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.5-p1
IBM QRadar Security Information and Event Manager=7.2.5-p2
IBM QRadar Security Information and Event Manager=7.2.5-p3
IBM QRadar Security Information and Event Manager=7.2.5-p4
IBM QRadar Security Information and Event Manager=7.2.5-p5
IBM QRadar Security Information and Event Manager=7.2.5-p6
IBM QRadar Security Information and Event Manager=7.2.6
IBM QRadar Security Information and Event Manager=7.2.6-p1
IBM QRadar Security Information and Event Manager=7.2.6-p2
IBM QRadar Security Information and Event Manager=7.2.6-p3
IBM QRadar Security Information and Event Manager=7.2.6-p4
IBM QRadar Security Information and Event Manager=7.2.6-p5
IBM QRadar Security Information and Event Manager=7.2.6-p6
IBM QRadar Security Information and Event Manager=7.2.6-p7
IBM QRadar Security Information and Event Manager=7.2.7
IBM QRadar Security Information and Event Manager=7.2.7-p1
IBM QRadar Security Information and Event Manager=7.2.7-p2
IBM QRadar Security Information and Event Manager=7.2.7-p3
IBM QRadar Security Information and Event Manager=7.2.7-p4
IBM QRadar Security Information and Event Manager=7.2.8
IBM QRadar Security Information and Event Manager=7.2.8-p1
IBM QRadar Security Information and Event Manager=7.2.8-p10
IBM QRadar Security Information and Event Manager=7.2.8-p11
IBM QRadar Security Information and Event Manager=7.2.8-p12
IBM QRadar Security Information and Event Manager=7.2.8-p13
IBM QRadar Security Information and Event Manager=7.2.8-p14
IBM QRadar Security Information and Event Manager=7.2.8-p15
IBM QRadar Security Information and Event Manager=7.2.8-p16
IBM QRadar Security Information and Event Manager=7.2.8-p2
IBM QRadar Security Information and Event Manager=7.2.8-p3
IBM QRadar Security Information and Event Manager=7.2.8-p4
IBM QRadar Security Information and Event Manager=7.2.8-p5
IBM QRadar Security Information and Event Manager=7.2.8-p6
IBM QRadar Security Information and Event Manager=7.2.8-p7
IBM QRadar Security Information and Event Manager=7.2.8-p8
IBM QRadar Security Information and Event Manager=7.2.8-p9
IBM QRadar Security Information and Event Manager=7.2.8.15
IBM QRadar Security Information and Event Manager=7.2.9
IBM QRadar Vulnerability Manager=7.2.0
IBM QRadar Vulnerability Manager=7.2.1
IBM QRadar Vulnerability Manager=7.2.2
IBM QRadar Vulnerability Manager=7.2.3
IBM QRadar Vulnerability Manager=7.2.4
IBM QRadar Vulnerability Manager=7.2.6-p1
IBM QRadar Vulnerability Manager=7.2.6-p2
IBM QRadar Vulnerability Manager=7.2.6-p3
IBM QRadar Vulnerability Manager=7.2.6-p4
IBM QRadar Vulnerability Manager=7.2.6-p5
IBM QRadar Vulnerability Manager=7.2.6-p6
IBM QRadar Vulnerability Manager=7.2.6-p7
IBM QRadar Vulnerability Manager=7.2.8
IBM QRadar Vulnerability Manager=7.2.8-p1
IBM QRadar Vulnerability Manager=7.2.8-p10
IBM QRadar Vulnerability Manager=7.2.8-p11
IBM QRadar Vulnerability Manager=7.2.8-p12
IBM QRadar Vulnerability Manager=7.2.8-p13
IBM QRadar Vulnerability Manager=7.2.8-p14
IBM QRadar Vulnerability Manager=7.2.8-p15
IBM QRadar Vulnerability Manager=7.2.8-p16
IBM QRadar Vulnerability Manager=7.2.8-p17
IBM QRadar Vulnerability Manager=7.2.8-p2
IBM QRadar Vulnerability Manager=7.2.8-p3
IBM QRadar Vulnerability Manager=7.2.8-p4
IBM QRadar Vulnerability Manager=7.2.8-p5
IBM QRadar Vulnerability Manager=7.2.8-p6
IBM QRadar Vulnerability Manager=7.2.8-p7
IBM QRadar Vulnerability Manager=7.2.8-p8
IBM QRadar Vulnerability Manager=7.2.8-p9
IBM SmartCloud Entry Appliance=2.3.0
IBM SmartCloud Entry Appliance=2.4.0
IBM SmartCloud Entry Appliance=3.1.0
IBM SmartCloud Entry Appliance=3.2.0
IBM SmartCloud Provisioning=2.1.0
IBM Software Defined Network for Virtual Environments<1.2.1
IBM Software Defined Network for Virtual Environments<1.2.1
IBM Software Defined Network for Virtual Environments<1.2.1
IBM Starter Kit for Cloud=2.2.0
IBM Workload Deployer>=3.1.0<=3.1.0.7
IBM Security Access Manager for Mobile=8.0.0.1
IBM Security Access Manager for Mobile=8.0.0.2
IBM Security Access Manager for Mobile=8.0.0.3
IBM Security Access Manager for Mobile=8.0.0.5
IBM Security Access Manager for Web 7.0=7.0.0.1
IBM Security Access Manager for Web 7.0=7.0.0.2
IBM Security Access Manager for Web 7.0=7.0.0.3
IBM Security Access Manager for Web 7.0=7.0.0.4
IBM Security Access Manager for Web 7.0=7.0.0.5
IBM Security Access Manager for Web 7.0=7.0.0.6
IBM Security Access Manager for Web 7.0=7.0.0.7
IBM Security Access Manager for Web 7.0=7.0.0.8
IBM Security Access Manager for Web 8.0=8.0.0.2
IBM Security Access Manager for Web 8.0=8.0.0.3
IBM Security Access Manager for Web 8.0=8.0.0.5
All of
Any of
IBM Storwize Unified V7000>=1.1.0.0<1.4.3.5
IBM Storwize Unified V7000>=1.5.0.0<1.5.0.4
IBM Storwize Unified V7000>=7.2.0.0<7.2.0.9
IBM Storwize Unified V7000>=7.3.0.0<7.3.0.7
IBM Storwize Unified V7000
All of
Any of
IBM Storwize V5000>=1.1.0.0<7.1.0.11
IBM Storwize V5000>=7.2.0.0<7.2.0.9
IBM Storwize V5000>=7.3.0.0<7.3.0.7
IBM Storwize
All of
Any of
IBM Storwize V3700 Firmware>=1.1.0.0<7.1.0.11
IBM Storwize V3700 Firmware>=7.2.0.0<7.2.0.9
IBM Storwize V3700 Firmware>=7.3.0.0<7.3.0.7
IBM Storwize
All of
Any of
IBM Storwize V3500 Software>=1.1.0.0<7.1.0.11
IBM Storwize V3500 Software>=7.2.0.0<7.2.0.9
IBM Storwize V3500 Software>=7.3.0.0<7.3.0.7
IBM Storwize V3500 Software
All of
Any of
IBM Flex System V7000 Firmware>=1.1.0.0<7.1.0.11
IBM Flex System V7000 Firmware>=7.2.0.0<7.2.0.9
IBM Flex System V7000 Firmware>=7.3.0.0<7.3.0.7
IBM Flex System V7000 Firmware
All of
Any of
IBM SAN Volume Controller Firmware>=1.1.0.0<7.1.0.11
IBM SAN Volume Controller Firmware>=7.2.0.0<7.2.0.9
IBM SAN Volume Controller Firmware>=7.3.0.0<7.3.0.7
IBM SAN Volume Controller Firmware
All of
Any of
IBM STN6500>=3.8.0.0<3.8.0.07
IBM STN6500>=3.9.1.0<3.9.1.08
IBM STN6500>=4.1.2.0<4.1.2.06
IBM STN6500 Firmware
All of
Any of
IBM STN6800>=3.8.0.0<3.8.0.07
IBM STN6800>=3.9.1.0<3.9.1.08
IBM STN6800>=4.1.2.0<4.1.2.06
IBM STN6800 firmware
All of
Any of
IBM STN7800>=3.8.0.0<3.8.0.07
IBM STN7800>=3.9.1.0<3.9.1.08
IBM STN7800>=4.1.2.0<4.1.2.06
IBM STN7800
Ubuntu Linux=10.04
Ubuntu Linux=12.04
Ubuntu Linux=14.04
Novell ZENworks Configuration Management=10.3
Novell ZENworks Configuration Management=11
Novell ZENworks Configuration Management=11.1
Novell ZENworks Configuration Management=11.2
Novell ZENworks Configuration Management=11.3.0
Novell Open Enterprise Server=2.0-sp3
Novell Open Enterprise Server=11.0-sp2
Check Point Security Gateway<r77.30
F5 Access Policy Manager>=10.1.0<=10.2.4
F5 Access Policy Manager>=11.0.0<=11.5.1
F5 Access Policy Manager=11.6.0
F5 BIG-IP Advanced Firewall Manager>=11.3.0<=11.5.1
F5 BIG-IP Advanced Firewall Manager=11.6.0
F5 BIG-IP Analytics>=11.0.0<=11.5.1
F5 BIG-IP Analytics=11.6.0
F5 BIG-IP Application Acceleration Manager>=11.4.0<=11.5.1
F5 BIG-IP Application Acceleration Manager=11.6.0
F5 Application Security Manager>=10.0.0<=10.2.4
F5 Application Security Manager>=11.0.0<=11.5.1
F5 Application Security Manager=11.6.0
F5 BIG-IP Edge Gateway>=10.1.0<=10.2.4
F5 BIG-IP Edge Gateway>=11.0.0<=11.3.0
Riverbed SteelApp Traffic Manager>=10.0.0<=10.2.4
Riverbed SteelApp Traffic Manager>=11.0.0<=11.5.1
Riverbed SteelApp Traffic Manager=11.6.0
F5 BIG-IP Link Controller>=10.0.0<=10.2.4
F5 BIG-IP Link Controller>=11.0.0<=11.5.1
F5 BIG-IP Link Controller=11.6.0
Riverbed SteelApp Traffic Manager>=10.0.0<=10.2.4
Riverbed SteelApp Traffic Manager>=11.0.0<=11.5.1
Riverbed SteelApp Traffic Manager=11.6.0
F5 BIG-IP Policy Enforcement Manager>=11.3.0<=11.5.1
F5 BIG-IP Policy Enforcement Manager=11.6.0
F5 BIG-IP Protocol Security Manager>=10.0.0<=10.2.4
F5 BIG-IP Protocol Security Manager>=11.0.0<=11.4.1
F5 BIG-IP WAN Optimization Manager>=10.0.0<=10.2.4
F5 BIG-IP WAN Optimization Manager>=11.0.0<=11.3.0
F5 BIG-IP WebAccelerator>=10.0.0<=10.2.4
F5 BIG-IP WebAccelerator>=11.0.0<=11.3.0
F5 BIG-IQ Cloud and Orchestration>=4.0.0<=4.4.0
F5 BIG-IQ Device>=4.2.0<=4.4.0
F5 BIG-IQ Security>=4.0.0<=4.4.0
F5 Enterprise Manager>=2.1.0<=2.3.0
F5 Enterprise Manager>=3.0.0<=3.1.1
F5 Traffix Systems Signaling Delivery Controller>=4.0.0<=4.0.5
F5 Traffix Systems Signaling Delivery Controller=3.3.2
F5 Traffix Systems Signaling Delivery Controller=3.4.1
F5 Traffix Systems Signaling Delivery Controller=3.5.1
F5 Traffix Systems Signaling Delivery Controller=4.1.0
All of
F5 ARX Firmware>=6.0.0<=6.4.0
F5 ARX Data Manager
All of
Any of
Citrix NetScaler SDX<9.3.67.5r1
Citrix NetScaler SDX>=10<10.1.129.11r1
Citrix NetScaler SDX>=10.5<10.5.52.11r1
Citrix NetScaler
Apple iOS and macOS>=10.0.0<10.10.0
VMware vCenter Server Appliance=5.0
VMware vCenter Server Appliance=5.0-update_1
VMware vCenter Server Appliance=5.0-update_2
VMware vCenter Server Appliance=5.1
VMware vCenter Server Appliance=5.1-update_1
VMware vCenter Server Appliance=5.1-update_2
VMware vCenter Server Appliance=5.5
VMware vCenter Server Appliance=5.5-update_1
VMware ESXi=4.0
VMware ESXi=4.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of CVE-2014-7169?

    The severity of CVE-2014-7169 is classified as critical due to the potential for remote code execution and the ability to manipulate files.

  • How do I fix CVE-2014-7169?

    To fix CVE-2014-7169, users should upgrade GNU Bash to version 4.3-026 or later.

  • What systems are affected by CVE-2014-7169?

    CVE-2014-7169 affects GNU Bash versions up to and including 4.3, as well as various systems that utilize Bash as their shell.

  • What does CVE-2014-7169 exploit in GNU Bash?

    CVE-2014-7169 exploits a vulnerability in how Bash processes environment variables, allowing attackers to execute arbitrary commands.

  • Can CVE-2014-7169 be exploited remotely?

    Yes, CVE-2014-7169 can be exploited remotely, making it critical for affected systems to be patched promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203