CVE-2014-7186: Buffer Overflow
Published Sep 28, 2014
·Updated
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redirstack" issue.
Affected Software
28 affected components
GNU Bash=1.14.0
GNU Bash=1.14.1
GNU Bash=1.14.2
GNU Bash=1.14.3
GNU Bash=1.14.4
GNU Bash=1.14.5
GNU Bash=1.14.6
GNU Bash=1.14.7
GNU Bash=2.0
GNU Bash=2.01
GNU Bash=2.01.1
GNU Bash=2.02
GNU Bash=2.02.1
GNU Bash=2.03
GNU Bash=2.04
GNU Bash=2.05
GNU Bash=2.05-a
GNU Bash=2.05-b
GNU Bash=3.0
GNU Bash=3.0.16
GNU Bash=3.1
GNU Bash=3.2
GNU Bash=3.2.48
GNU Bash=4.0
GNU Bash=4.0-rc1
GNU Bash=4.1
GNU Bash=4.2
GNU Bash=4.3
Event History
Sep 28, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7186?
CVE-2014-7186 has been rated as a high severity vulnerability due to the potential for denial of service effects.
2
How do I fix CVE-2014-7186?
To fix CVE-2014-7186, update GNU Bash to a version later than 4.3.
3
What type of vulnerability is CVE-2014-7186?
CVE-2014-7186 is a denial of service vulnerability caused by out-of-bounds array access.
4
Who is affected by CVE-2014-7186?
CVE-2014-7186 affects multiple versions of GNU Bash, specifically versions 1.14.0 to 4.3.
5
What are the consequences of exploiting CVE-2014-7186?
Exploiting CVE-2014-7186 can lead to application crashes and potentially other unspecified impacts.