Skip to main content

CVE detail

CVE-2014-7169

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVSS 9.8 · CriticalBuzz score 63.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 63.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 29.4 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
29.4
18 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
18 source links · newest first
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these […]

    newssecurityaffairs.comOct 4, 2025, 3:49 PM
  • The last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]

    newswww.csoonline.comJul 19, 2022, 9:00 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of eight more vulnerabilities to the list of security flaws known to be exploited in malicious attacks.

    newswww.securityweek.comFeb 1, 2022, 11:12 AM
  • The US CISA added eight more flaws to its Known Exploited Vulnerabilities Catalog that are known to be used in attacks in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added eight more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that […]

    newssecurityaffairs.comJan 31, 2022, 9:05 PM
  • Top Cybersecurity Headlines of 2014SecurityWeek

    Data breaches, dangerous vulnerabilities and more dominated the headlines this year in cybersecurity.

    newswww.securityweek.comDec 30, 2014, 10:10 PM
  • It appears that 2014 will be remembered in the IT industry for several severe and wide-reaching server-side vulnerabilities. In April, a serious flaw ( CVE-2014-0160 ) in the widely-used OpenSSL encryption software that protects website traffic shook the industry (a.k.a. Heartbleed), leaving hundreds of thousands of systems open to attacks from cybercriminals. More than six months later, thousands of websites and devices still remain vulnerable . In September, multiple critical vulnerabilities ( CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE 2014-6278 ) were reported in the GNU Bourne-Again Shell (Bash), the common command-line shell used in many Linux / UNIX operating systems and Apple’s Mac OS X. The flaws could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system. Similar to Heartbleed, these flaws affect a broad range of systems, including but not limited to Apache…

    newswww.securityweek.comNov 5, 2014, 3:18 PM
  • The GNU Bash vulnerability dubbed ShellShock affects a wide range of software solutions, including some industrial products developed by the German engineering and electronics giant Siemens.

    newswww.securityweek.comOct 8, 2014, 6:47 PM
  • The security researcher Michal Zalewski revealed the details of other two additional bugs he discovered in the Bourne Again Shell after the Bash Bug case. IT community worldwide has been shocked by the discovery of the Bash Bug flaw, a vulnerability that was present in the popular Bash component for more than two decades. While principal […]

    newssecurityaffairs.comOct 5, 2014, 1:28 PM
  • Joining several major tech companies, VMware has started rolling out software updates that address the recently discovered GNU Bash vulnerability dubbed ShellShock.

    newswww.securityweek.comOct 2, 2014, 1:41 PM
  • Ever since the existence of the GNU Bash flaw ( Shellshock ) came to light last week, threat actors have been searching for vulnerable machines that they can exploit for various purposes, Incapsula said on Monday.

    newswww.securityweek.comSep 30, 2014, 9:42 AM
  • Apple patches Shellshock bug in OS XHelp Net Security

    Apple has finally released a security update for OS X that will close up the critical remote code execution Shellshock bug found in the GNU Bash UNIX shell. The update resolves both the CVE-2014-6271 issue discovered by Stephane Chazelas, as well as the CVE-2014-7169 one flagged by Tavis Ormandy. Security updates have been provided for OS X Mavericks, Mountain Lion, and Lion users. According to Ars Technica, the patch will not be provided for current … More →

    newswww.helpnetsecurity.comSep 30, 2014, 4:54 AM
  • The number of attempts by hackers to compromise computers through the Shellshock vulnerability is rising, but companies have options for defending against attackers. Shellshock is the name given to a set of at least six vulnerabilities in GNU Bash, the default command shell found in Linux, Unix and Mac OS X. The flaws in Bash, […]

    newswww.csoonline.comSep 30, 2014, 12:58 AM
  • Several organizations that use the GNU Bourne Again Shell (Bash) in their products have been hard at work producing software updates to address the recently discovered vulnerability dubbed “ Shellshock ” or “Bash Bug.” GNU Bash is a command-line shell used in Linux, Unix and Mac OS X operating systems which is installed not only on personal computers and servers, but also installed on other connected “Internet of Things” (IoT) devices. The vulnerability ( CVE-2014-6271 ) affects version 1.14 and later of the shell and can be exploited to execute arbitrary commands and take over affected machines. Red Hat published a security update shortly after the existence of Shellshock came to light. However, it soon became clear that the fix had been incomplete since, according to Red Hat, “Bash still allowed certain characters to be injected into other environments via specially crafted environment variables.” This second issue has been assigned CVE-2014-7169 . On Friday, both Red Hat and Fedora…

    newswww.securityweek.comSep 29, 2014, 11:22 AM
  • Bash Shellshock bug: More attacks, more patchesHelp Net Security

    As vendors scramble to issue patches for the GNU Bash Shellshock bug and companies rush to implement them, attackers around the world are probing systems for the hole it opens. Initial attacks geared towards creating DDoS botnets managed via IRC have been followed by reconnaissance attempts in Brazil and China, where the IPs of various institutions (including financial) have been probed and, after found vulnerable to the bug, the attackers “asked” the target servers for … More →

    newswww.helpnetsecurity.comSep 29, 2014, 11:17 AM
  • From Thursday on, several security firms reported a drastic uptick in the number of attacks that leverage the recently disclosed vulnerability in GNU Bash (CVE-2014-6271), widely known as Shellshock. On Friday, AlienVault labs reported that the flaw was being used by two attackers to install two different pieces of malware on the victim system. One […]

    newswww.csoonline.comSep 29, 2014, 11:00 AM
  • Apple says users of its OS X are “safe by default” from the Bash Bug, meanwhile Oracle warns its customers that 32 products are affected by the flaw. The recently discovered Bash Bug vulnerability is menacing billions of devices that could be exposed to cyber attacks which exploit the flaw, the situation appears to be critical […]

    newssecurityaffairs.comSep 28, 2014, 7:56 AM
  • Bash “Shellshock” bug: Who needs to worry?Help Net Security

    As expected, attackers have begun exploiting the GNU Bash “Shellshock” remote code execution bug (CVE-2014-6271) to compromise systems and infect them with malware. After the disclosure of its existence, Alien Vault has begun running a new module in their honeypots and waiting for attackers aiming to exploit this vulnerability. “We have had several hits in the last 24 hours. Most of them are systems trying to detect if the system is vulnerable and they simple … More →

    newswww.helpnetsecurity.comSep 26, 2014, 8:49 AM
  • Beating back the recently disclosed GNU Bourne Again Shell (Bash) vulnerability may not be as easy as some hoped.

    newswww.securityweek.comSep 25, 2014, 11:09 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence