bash: off-by-one error in deeply nested flow control constructs
Published Sep 28, 2014
10.0
HIGHCVSS 2.0
EPSS 64.62%
Description
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
Affected products
No data.
- 1.14.0
- 1.14.1
- 1.14.2
- 1.14.3
- 1.14.4
- 1.14.5
- 1.14.6
- 1.14.7
- 2.0
- 2.01
- 2.01.1
- 2.02
- 2.02.1
- 2.03
- 2.04
- 2.05
- 2.05
- 2.05
- 3.0
- 3.0.16
- 3.1
- 3.2
- 3.2.48
- 4.0
- 4.0
- 4.1
- 4.2
- 4.3
No data.
RHEV Manager version 3.4
rhev-hypervisor6-0:6.5-20140930.1.el6ev
Fixed · RHSA-2014:1354
Red Hat Enterprise Linux 4 Extended Lifecycle Support
bash-0:3.0-27.el4.4
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 5
bash-0:3.2-33.el5_11.4
Fixed · RHSA-2014:1306
Red Hat Enterprise Linux 5.6 Long Life
bash-0:3.2-24.el5_6.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 5.9 Extended Update Support
bash-0:3.2-32.el5_9.3
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 6
bash-0:4.1.2-15.el6_5.2
Fixed · RHSA-2014:1306
Red Hat Enterprise Linux 6.2 Advanced Update Support
bash-0:4.1.2-9.el6_2.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 6.4 Extended Update Support
bash-0:4.1.2-15.el6_4.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 7
bash-0:4.2.45-5.el7_0.4
Fixed · RHSA-2014:1306
S-JIS for RHEL 5.9.Z
bash-0:3.2-32.el5_9.3.sjis.1
Fixed · RHSA-2014:1865
S-JIS for Red Hat Enteprise Linux 5
bash-0:3.2-33.el5_11.1.sjis.2
Fixed · RHSA-2014:1312
S-JIS for Red Hat Enteprise Linux 6
bash-0:4.1.2-15.el6_5.1.sjis.2
Fixed · RHSA-2014:1312
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV Manager version 3.4 | rhev-hypervisor6-0:6.5-20140930.1.el6ev | Fixed | RHSA-2014:1354 |
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | bash-0:3.0-27.el4.4 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 5 | bash-0:3.2-33.el5_11.4 | Fixed | RHSA-2014:1306 |
| Red Hat Enterprise Linux 5.6 Long Life | bash-0:3.2-24.el5_6.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | bash-0:3.2-32.el5_9.3 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 6 | bash-0:4.1.2-15.el6_5.2 | Fixed | RHSA-2014:1306 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | bash-0:4.1.2-9.el6_2.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | bash-0:4.1.2-15.el6_4.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 7 | bash-0:4.2.45-5.el7_0.4 | Fixed | RHSA-2014:1306 |
| S-JIS for RHEL 5.9.Z | bash-0:3.2-32.el5_9.3.sjis.1 | Fixed | RHSA-2014:1865 |
| S-JIS for Red Hat Enteprise Linux 5 | bash-0:3.2-33.el5_11.1.sjis.2 | Fixed | RHSA-2014:1312 |
| S-JIS for Red Hat Enteprise Linux 6 | bash-0:4.1.2-15.el6_5.1.sjis.2 | Fixed | RHSA-2014:1312 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security does not consider this bug to have any security impact on the bash packages shipped in Red Hat Enterprise Linux. A fix for this issue was applied as a hardening in RHSA-2014:1306, RHSA-2014:1311, and RHSA-2014:1312.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (46 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 64.62% (0.64622) | 99.22th | v5 (v2026.06.15) |
| Sep 20, 2026 | 64.62% (0.64622) | 99.20th | v5 (v2026.06.15) |
| Jun 15, 2026 | 58.46% (0.58462) | 98.98th | v5 (v2026.06.15) |
| Mar 4, 2026 | 90.61% (0.90614) | 99.61th | v4 (v2025.03.14) |
| Mar 3, 2026 | 88.15% (0.88147) | 99.48th | v4 (v2025.03.14) |
| Mar 1, 2026 | 89.38% (0.89375) | 99.54th | v4 (v2025.03.14) |
| Feb 4, 2026 | 91.95% (0.91953) | 99.68th | v4 (v2025.03.14) |
| Feb 1, 2026 | 90.33% (0.90335) | 99.59th | v4 (v2025.03.14) |
| Jan 21, 2026 | 91.95% (0.91953) | 99.68th | v4 (v2025.03.14) |
| Jan 4, 2026 | 89.37% (0.89369) | 99.52th | v4 (v2025.03.14) |
| Jan 1, 2026 | 86.21% (0.86211) | 99.38th | v4 (v2025.03.14) |
| Dec 4, 2025 | 89.37% (0.89369) | 99.52th | v4 (v2025.03.14) |
| Dec 1, 2025 | 86.21% (0.86211) | 99.37th | v4 (v2025.03.14) |
| Nov 4, 2025 | 89.37% (0.89369) | 99.52th | v4 (v2025.03.14) |
| Nov 1, 2025 | 86.21% (0.86211) | 99.37th | v4 (v2025.03.14) |
| Oct 4, 2025 | 89.37% (0.89369) | 99.52th | v4 (v2025.03.14) |
| Oct 1, 2025 | 86.21% (0.86211) | 99.38th | v4 (v2025.03.14) |
| Sep 4, 2025 | 90.10% (0.90099) | 99.57th | v4 (v2025.03.14) |
| Sep 1, 2025 | 87.39% (0.87388) | 99.43th | v4 (v2025.03.14) |
| Aug 4, 2025 | 90.10% (0.90099) | 99.56th | v4 (v2025.03.14) |
| Aug 1, 2025 | 87.39% (0.87388) | 99.43th | v4 (v2025.03.14) |
| Jul 4, 2025 | 90.10% (0.90099) | 99.56th | v4 (v2025.03.14) |
| Jul 1, 2025 | 87.39% (0.87388) | 99.42th | v4 (v2025.03.14) |
| Jun 4, 2025 | 90.10% (0.90099) | 99.56th | v4 (v2025.03.14) |
| Jun 1, 2025 | 87.39% (0.87388) | 99.42th | v4 (v2025.03.14) |
| May 5, 2025 | 90.10% (0.90099) | 99.54th | v4 (v2025.03.14) |
| May 1, 2025 | 87.39% (0.87388) | 99.41th | v4 (v2025.03.14) |
| Apr 20, 2025 | 90.10% (0.90099) | 99.54th | v4 (v2025.03.14) |
| Apr 19, 2025 | 87.39% (0.87388) | 99.39th | v4 (v2025.03.14) |
| Apr 16, 2025 | 90.10% (0.90099) | 99.54th | v4 (v2025.03.14) |
| Apr 15, 2025 | 87.39% (0.87388) | 99.39th | v4 (v2025.03.14) |
| Apr 14, 2025 | 90.10% (0.90099) | 99.57th | v4 (v2025.03.14) |
| Apr 13, 2025 | 87.39% (0.87388) | 99.42th | v4 (v2025.03.14) |
| Apr 2, 2025 | 90.10% (0.90099) | 99.57th | v4 (v2025.03.14) |
| Apr 1, 2025 | 87.39% (0.87388) | 99.42th | v4 (v2025.03.14) |
| Mar 22, 2025 | 90.10% (0.90099) | 99.59th | v4 (v2025.03.14) |
| Mar 19, 2025 | 87.39% (0.87388) | 99.42th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.77% (0.90765) | 99.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.31% (0.97311) | 99.91th | v3 (v2023.03.01) |
| Jun 24, 2024 | 97.28% (0.97281) | 99.86th | v3 (v2023.03.01) |
| May 10, 2024 | 97.34% (0.97343) | 99.89th | v3 (v2023.03.01) |
| Mar 24, 2024 | 97.37% (0.97368) | 99.89th | v3 (v2023.03.01) |
| Jul 19, 2023 | 97.38% (0.97379) | 99.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.42% (0.97422) | 99.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 31.50% (0.31500) | 97.57th | v2 (v2022.01.01) |
| Feb 4, 2022 | 31.50% (0.31500) | 96.47th | v2 (v2022.01.01) |
References (127)
- http://jvn.jp/en/jp/JVN55667175/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 third-party-advisoryx_refsource_JVNDB
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=141330468527613&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141345648114150&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383026420882&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383081521087&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383138121313&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383196021590&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383244821813&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383304022067&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141450491804793&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141576728022234&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577137423233&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577241923505&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577297623641&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141585637922673&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141694386919794&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141879528318582&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142118135300698&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142289270617409&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358026505815&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358078406056&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142721162228379&w=2 vendor-advisoryx_refsource_HP
- http://openwall.com/lists/oss-security/2014/09/25/32 mailing-listx_refsource_MLISTExploit
- http://openwall.com/lists/oss-security/2014/09/26/2 mailing-listx_refsource_MLIST
- http://openwall.com/lists/oss-security/2014/09/28/10 mailing-listx_refsource_MLIST
- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html x_refsource_MISC
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2014-1311.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1312.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1354.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/fulldisclosure/2014/Oct/0 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/58200 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59907 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60024 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60034 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60044 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60055 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60063 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60193 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60433 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61065 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61128 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61129 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61188 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61283 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61287 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61291 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61313 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61328 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61442 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61479 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61485 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61503 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61550 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61552 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61565 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61603 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61618 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61622 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61633 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61636 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61641 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61643 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61654 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61703 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61816 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61855 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61857 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61873 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62343 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/HT204244 x_refsource_CONFIRM
- http://support.novell.com/security/cve/CVE-2014-7187.html x_refsource_CONFIRM
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash vendor-advisoryx_refsource_CISCO
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686084 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686447 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079 x_refsource_CONFIRM
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/support/kb/doc.php?id=7015721 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html x_refsource_CONFIRM
- http://www.qnap.com/i/en/support/con_show.php?cid=61 x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/533593/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.ubuntu.com/usn/USN-2364-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2014-0010.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2014-7187 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1146804 Issue Tracking
- https://kb.bluecoat.com/index?page=content&id=SA82 x_refsource_CONFIRM
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-7187
- https://support.apple.com/HT205267 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200217 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200223 x_refsource_CONFIRM
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 x_refsource_CONFIRM
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-7187
- https://www.suse.com/support/shellshock/ x_refsource_CONFIRM
Change history (0)
No recorded changes yet.