Description
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Exploits & proofs of concept
- exploit-dbQmail SMTP - Bash Environment Variable Injection (Metasploit)by Metasploit
- exploit-dbRedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injectionby Hacker Fantastic
- exploit-dbTrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injectionby Hacker Fantastic
- exploit-dbIPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)by Metasploit
- exploit-dbAdvantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)by Metasploit
- exploit-dbCisco Unified Communications Manager - Multiple Vulnerabilitiesby Bernhard Mueller
- exploit-dbKemp Load Master 7.1.16 - Multiple Vulnerabilitiesby Roberto Suggi Liverani
- exploit-dbQNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)by Patrick Pellegrino
- exploit-dbQNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)by Patrick Pellegrino
- exploit-dbPHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injectionby Ryan King (Starfall)
- exploit-dbCUPS Filter - Bash Environment Variable Code Injection (Metasploit)by Metasploit
- exploit-dbPostfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injectionby Phil Blank
- exploit-dbApache mod_cgi - 'Shellshock' Remote Command Injectionby Federico Galatolo
- exploit-dbBash CGI - 'Shellshock' Remote Command Injection (Metasploit)by Fady Mohammed Osman
- exploit-dbOpenVPN 2.2.29 - 'Shellshock' Remote Command Injectionby hobbily plunt
- exploit-dbPure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)by Metasploit
- exploit-dbGNU bash 4.3.11 - Environment Variable dhclientby @0x00string
- exploit-dbIPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injectionby Claudio Viviani
- exploit-dbGNU Bash - 'Shellshock' Environment Variable Command Injectionby Stephane Chazelas
- exploit-dbBash - 'Shellshock' Environment Variables Command Injectionby Prakhar Prasad & Subho Halder
- exploit-dbGNU Bash - Environment Variable Command Injection (Metasploit)by Shaun Colley
- nucleiShellShock - Remote Code Executionby pentest_swissky,0xelkomy
References
- EXPLOIThttps://www.exploit-db.com/exploits/37816/
- EXPLOIThttp://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00034.html
- MISChttp://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21685749
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141577137423233&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142719845423222&w=2
- EXPLOIThttps://www.exploit-db.com/exploits/39918/
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141216668515282&w=2
- MISChttp://rhn.redhat.com/errata/RHSA-2014-1295.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html
- MISChttps://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/
- MISChttps://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383138121313&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142721162228379&w=2
- MISChttp://www.securityfocus.com/archive/1/533593/100/0/threaded
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142358026505815&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686084
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686479
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142719845423222&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61188
- MISChttp://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
- MISChttp://jvn.jp/en/jp/JVN55667175/index.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61676
- EXPLOIThttps://www.exploit-db.com/exploits/40619/
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/60433
- EXPLOIThttps://www.exploit-db.com/exploits/38849/
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383026420882&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141585637922673&w=2
- MISChttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00049.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141576728022234&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21685541
- VENDOR_ADVISORYhttp://secunia.com/advisories/61715
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61816
- MAILING_LISThttp://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61442
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142358078406056&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142805027510172&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61283
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142113462216480&w=2
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-2362-1
- MISChttps://kc.mcafee.com/corporate/index?page=content&id=SB10085
- MAILING_LISThttp://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61654
- VENDOR_ADVISORYhttp://secunia.com/advisories/61542
- MISChttp://www.novell.com/support/kb/doc.php?id=7015701
- MISChttp://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315
- VENDOR_ADVISORYhttp://secunia.com/advisories/62312
- VENDOR_ADVISORYhttp://secunia.com/advisories/59272
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141319209015420&w=2
- MISChttps://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141879528318582&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21685604
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142118135300698&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61703
- VENDOR_ADVISORYhttp://support.apple.com/kb/HT6495
- MISChttp://www.kb.cert.org/vuls/id/252743
- VENDOR_ADVISORYhttp://secunia.com/advisories/61065
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383196021590&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383081521087&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686445
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686131
- MISChttp://www.securityfocus.com/bid/70103
- MISChttp://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141879528318582&w=2
- MISChttp://www.us-cert.gov/ncas/alerts/TA14-268A
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61641
- MISChttps://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648
- VENDOR_ADVISORYhttps://access.redhat.com/node/1200223
- EXPLOIThttp://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html
- MISChttp://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898
- MISChttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21685914
- MAILING_LISThttp://seclists.org/fulldisclosure/2014/Oct/0
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:164
- MISChttp://rhn.redhat.com/errata/RHSA-2014-1293.html
- MISChttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00040.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142721162228379&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/60325
- MISChttps://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
- VENDOR_ADVISORYhttp://secunia.com/advisories/60024
- EXPLOIThttp://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html
- EXPLOIThttps://www.exploit-db.com/exploits/34879/
- VENDOR_ADVISORYhttps://access.redhat.com/articles/1200223
- VENDOR_ADVISORYhttp://secunia.com/advisories/62343
- VENDOR_ADVISORYhttp://secunia.com/advisories/61565
- MISChttps://www.suse.com/support/shellshock/
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141450491804793&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61313
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142358026505815&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61873
- VENDOR_ADVISORYhttp://secunia.com/advisories/61485
- VENDOR_ADVISORYhttp://secunia.com/advisories/60947
- MISChttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183
- VENDOR_ADVISORYhttps://support.apple.com/kb/HT6535
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141577297623641&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142546741516006&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=isg3T1021272
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383244821813&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61312
- VENDOR_ADVISORYhttp://secunia.com/advisories/60193
- VENDOR_ADVISORYhttp://www.vmware.com/security/advisories/VMSA-2014-0010.html
- VENDOR_ADVISORYhttp://linux.oracle.com/errata/ELSA-2014-1294.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/60063
- EXPLOIThttp://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/60034
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141330425327438&w=2
- MISChttp://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/59907
- VENDOR_ADVISORYhttp://secunia.com/advisories/58200
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141577241923505&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61643
- MISChttp://www.novell.com/support/kb/doc.php?id=7015721
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21687079
- VENDOR_ADVISORYhttp://secunia.com/advisories/61503
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686246
- MISChttp://rhn.redhat.com/errata/RHSA-2014-1354.html
- EXPLOIThttps://www.exploit-db.com/exploits/40938/
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141216207813411&w=2
- MISChttp://support.novell.com/security/cve/CVE-2014-6271.html
- MISChttp://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915
- VENDOR_ADVISORYhttp://secunia.com/advisories/61547
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383465822787&w=2
- MISChttp://www.qnap.com/i/en/support/con_show.php?cid=61
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141694386919794&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61552
- VENDOR_ADVISORYhttp://secunia.com/advisories/61780
- MISChttp://www-01.ibm.com/support/docview.wss?uid=isg3T1021279
- MISChttps://support.citrix.com/article/CTX200223
- VENDOR_ADVISORYhttp://www.debian.org/security/2014/dsa-3032
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686447
- VENDOR_ADVISORYhttp://secunia.com/advisories/62228
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141330468527613&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61855
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141235957116749&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/60044
- VENDOR_ADVISORYhttp://secunia.com/advisories/61291
- MISChttp://rhn.redhat.com/errata/RHSA-2014-1294.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141345648114150&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/59737
- VENDOR_ADVISORYhttp://secunia.com/advisories/61287
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383353622268&w=2
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142118135300698&w=2
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=1141597
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142118135300698&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/61711
- MAILING_LISThttp://marc.info/?l=bugtraq&m=142113462216480&w=2
- MISChttp://www-01.ibm.com/support/docview.wss?uid=isg3T1021361
- MAILING_LISThttp://marc.info/?l=bugtraq&m=141383304022067&w=2
- VENDOR_ADVISORYhttp://advisories.mageia.org/MGASA-2014-0388.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/61128
- MISChttps://support.citrix.com/article/CTX200217
- VENDOR_ADVISORYhttp://secunia.com/advisories/61471
- VENDOR_ADVISORYhttp://secunia.com/advisories/60055
- VENDOR_ADVISORYhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash
- VENDOR_ADVISORYhttp://secunia.com/advisories/61550
- VENDOR_ADVISORYhttp://secunia.com/advisories/61633
- VENDOR_ADVISORYhttp://linux.oracle.com/errata/ELSA-2014-1293.html
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21686494
- MISChttps://kb.bluecoat.com/index?page=content&id=SA82
- VENDOR_ADVISORYhttp://secunia.com/advisories/61328
- MISChttp://www-01.ibm.com/support/docview.wss?uid=swg21685733
- EXPLOIThttps://www.exploit-db.com/exploits/42938/
- VENDOR_ADVISORYhttp://secunia.com/advisories/61129
- VENDOR_ADVISORYhttp://secunia.com/advisories/61700
- VENDOR_ADVISORYhttp://secunia.com/advisories/61603
- VENDOR_ADVISORYhttp://secunia.com/advisories/61857
- MISChttp://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879
- EXPLOIThttp://packetstormsecurity.com/files/161107/SonicWall-SSL-VPN-Shellshock-Remote-Code-Execution.html
- VENDOR_ADVISORYhttps://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006
Updated 21m ago · 8 sources