CVE-2014-7187: Buffer Overflow
Off-by-one error in the readtokenword function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "wordlineno" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7187?
CVE-2014-7187 is classified as a denial of service vulnerability due to its potential to cause application crashes.
How do I fix CVE-2014-7187?
To fix CVE-2014-7187, update GNU Bash to a version that is patched for this vulnerability, specifically version 4.3 or later.
Which versions of GNU Bash are affected by CVE-2014-7187?
CVE-2014-7187 affects GNU Bash versions up to and including 4.3.
What types of attacks can exploit CVE-2014-7187?
CVE-2014-7187 can be exploited by an attacker through deeply nested for loops, leading to out-of-bounds array access.
Is user interaction required to exploit CVE-2014-7187?
No user interaction is required to exploit CVE-2014-7187 as it can be triggered remotely.