bash: uninitialized here document closing delimiter pointer use
Published Sep 27, 2014
10.0
HIGHCVSS 2.0
EPSS 69.77%
Description
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
Affected products
No data.
- 1.14.0
- 1.14.1
- 1.14.2
- 1.14.3
- 1.14.4
- 1.14.5
- 1.14.6
- 1.14.7
- 2.0
- 2.01
- 2.01.1
- 2.02
- 2.02.1
- 2.03
- 2.04
- 2.05
- 2.05
- 2.05
- 3.0
- 3.0.16
- 3.1
- 3.2
- 3.2.48
- 4.0
- 4.0
- 4.1
- 4.2
- 4.3
No data.
Red Hat Enterprise Linux 4
bash
Not affected
Red Hat Enterprise Linux 5
bash
Not affected
Red Hat Enterprise Linux 6
bash
Not affected
Red Hat Enterprise Linux 7
bash
Not affected
Red Hat Enterprise Virtualization 3
rhev-hypervisor
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | bash | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bash | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bash | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bash | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat no longer considers this bug to be a security issue. The change introduced in bash errata RHSA-2014:1306, RHSA-2014:1311 and RHSA-2014:1312 removed the exposure of the bash parser to untrusted input, mitigating this problem to a bug without security impact.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (46 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 69.77% (0.69775) | 99.35th | v5 (v2026.06.15) |
| Sep 20, 2026 | 69.77% (0.69775) | 99.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 64.33% (0.64326) | 99.13th | v5 (v2026.06.15) |
| Jun 3, 2026 | 86.75% (0.86752) | 99.44th | v4 (v2025.03.14) |
| May 22, 2026 | 87.95% (0.87951) | 99.49th | v4 (v2025.03.14) |
| Apr 13, 2026 | 86.54% (0.86544) | 99.42th | v4 (v2025.03.14) |
| Mar 4, 2026 | 87.82% (0.87816) | 99.46th | v4 (v2025.03.14) |
| Mar 1, 2026 | 84.90% (0.84902) | 99.33th | v4 (v2025.03.14) |
| Feb 4, 2026 | 87.82% (0.87816) | 99.45th | v4 (v2025.03.14) |
| Feb 1, 2026 | 84.90% (0.84902) | 99.33th | v4 (v2025.03.14) |
| Jan 21, 2026 | 87.82% (0.87816) | 99.45th | v4 (v2025.03.14) |
| Jan 4, 2026 | 85.13% (0.85132) | 99.32th | v4 (v2025.03.14) |
| Jan 1, 2026 | 81.25% (0.81250) | 99.14th | v4 (v2025.03.14) |
| Dec 4, 2025 | 85.13% (0.85132) | 99.31th | v4 (v2025.03.14) |
| Dec 1, 2025 | 81.25% (0.81250) | 99.13th | v4 (v2025.03.14) |
| Nov 4, 2025 | 85.13% (0.85132) | 99.30th | v4 (v2025.03.14) |
| Nov 1, 2025 | 81.25% (0.81250) | 99.12th | v4 (v2025.03.14) |
| Oct 4, 2025 | 85.13% (0.85132) | 99.31th | v4 (v2025.03.14) |
| Oct 1, 2025 | 81.25% (0.81250) | 99.14th | v4 (v2025.03.14) |
| Sep 16, 2025 | 85.13% (0.85132) | 99.31th | v4 (v2025.03.14) |
| Sep 4, 2025 | 86.46% (0.86460) | 99.37th | v4 (v2025.03.14) |
| Sep 1, 2025 | 83.10% (0.83105) | 99.23th | v4 (v2025.03.14) |
| Aug 4, 2025 | 86.46% (0.86460) | 99.37th | v4 (v2025.03.14) |
| Aug 1, 2025 | 83.10% (0.83105) | 99.22th | v4 (v2025.03.14) |
| Jul 4, 2025 | 86.46% (0.86460) | 99.36th | v4 (v2025.03.14) |
| Jul 1, 2025 | 83.10% (0.83105) | 99.21th | v4 (v2025.03.14) |
| Jun 6, 2025 | 86.46% (0.86460) | 99.35th | v4 (v2025.03.14) |
| Jun 4, 2025 | 84.03% (0.84034) | 99.24th | v4 (v2025.03.14) |
| Jun 1, 2025 | 79.73% (0.79727) | 99.04th | v4 (v2025.03.14) |
| May 15, 2025 | 84.03% (0.84034) | 99.23th | v4 (v2025.03.14) |
| May 11, 2025 | 79.73% (0.79727) | 99.02th | v4 (v2025.03.14) |
| May 4, 2025 | 84.03% (0.84034) | 99.23th | v4 (v2025.03.14) |
| May 1, 2025 | 79.73% (0.79727) | 99.02th | v4 (v2025.03.14) |
| Apr 17, 2025 | 84.03% (0.84034) | 99.22th | v4 (v2025.03.14) |
| Apr 16, 2025 | 79.73% (0.79727) | 99.01th | v4 (v2025.03.14) |
| Mar 31, 2025 | 84.03% (0.84034) | 99.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 79.73% (0.79727) | 99.04th | v4 (v2025.03.14) |
| Mar 22, 2025 | 84.03% (0.84034) | 99.29th | v4 (v2025.03.14) |
| Mar 21, 2025 | 79.73% (0.79727) | 99.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 84.03% (0.84034) | 99.26th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.31% (0.97309) | 99.90th | v3 (v2023.03.01) |
| Jun 23, 2024 | 97.26% (0.97256) | 99.85th | v3 (v2023.03.01) |
| Jul 18, 2023 | 97.31% (0.97309) | 99.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.36% (0.97362) | 99.79th | v3 (v2023.03.01) |
| Mar 6, 2023 | 63.51% (0.63509) | 98.99th | v2 (v2022.01.01) |
| Feb 4, 2022 | 63.51% (0.63509) | 98.74th | v2 (v2022.01.01) |
References (113)
- http://jvn.jp/en/jp/JVN55667175/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 third-party-advisoryx_refsource_JVNDB
- http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html x_refsource_MISCExploitPatch
- http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html x_refsource_MISC
- http://linux.oracle.com/errata/ELSA-2014-3093 x_refsource_CONFIRM
- http://linux.oracle.com/errata/ELSA-2014-3094 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=141330468527613&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141345648114150&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383026420882&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383081521087&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383196021590&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383244821813&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383304022067&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383353622268&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383465822787&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141450491804793&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141576728022234&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577137423233&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577241923505&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577297623641&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141585637922673&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141879528318582&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142118135300698&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142289270617409&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358026505815&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358078406056&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142721162228379&w=2 vendor-advisoryx_refsource_HP
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html x_refsource_MISC
- http://secunia.com/advisories/58200 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59907 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59961 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60024 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60034 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60044 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60055 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60063 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60193 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60325 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60433 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61065 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61128 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61129 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61283 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61287 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61291 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61313 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61328 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61442 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61471 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61485 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61503 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61550 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61552 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61565 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61603 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61633 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61641 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61643 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61654 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61703 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61780 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61816 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61857 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62343 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/HT204244 x_refsource_CONFIRM
- http://support.novell.com/security/cve/CVE-2014-6277.html x_refsource_CONFIRM
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash vendor-advisoryx_refsource_CISCO
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685541 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079 x_refsource_CONFIRM
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/support/kb/doc.php?id=7015721 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html x_refsource_CONFIRM
- http://www.qnap.com/i/en/support/con_show.php?cid=61 x_refsource_CONFIRM
- http://www.ubuntu.com/usn/USN-2380-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2014-0010.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2014-6277 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1147189 Issue Tracking
- https://kb.bluecoat.com/index?page=content&id=SA82 x_refsource_CONFIRM
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-6277
- https://support.apple.com/HT205267 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200217 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200223 x_refsource_CONFIRM
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 x_refsource_CONFIRM
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-6277
- https://www.suse.com/support/shellshock/ x_refsource_CONFIRM
Change history (0)
No recorded changes yet.