DEBIAN-CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | bash | 0, 0, 0 |
| Debian:11 | bash | 0, 0, 0 |
| Debian:12 | bash | 0, 0, 0 |
| Debian:14 | bash | 0, 0, 0 |
Exploit Intelligence
- Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi (github-poc)
- its simple Shellshock exploit (github-poc)
- Reflyzal106/Cve-2014-Error-What-Is-The-Cve-2014-6271-Bash-Vulnerability (github-poc)
- "A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors." (github-poc)
- Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico (github-poc-repo)
- Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico (github-poc)
- Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation. (github-poc)
- its simple Shellshock exploit (github-poc)
- End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271). (github-poc)
- kaleth4/CVE-2014-6271 (github-poc)
…and 103 more exploits
Timeline
- Sep 24, 2014 CVE Published
- Jan 17, 2015 PoC Published
- Apr 28, 2026 CVE Updated