Lucene search

K
cve[email protected]CVE-2014-7186
HistorySep 28, 2014 - 7:55 p.m.

CVE-2014-7186

2014-09-2819:55:06
CWE-119
web.nvd.nist.gov
174
cve-2014-7186
gnu bash
parse.y
denial of service
remote attackers
application crash
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.975 High

EPSS

Percentile

100.0%

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the “redir_stack” issue.

Affected configurations

NVD
Node
gnubashMatch1.14.0
OR
gnubashMatch1.14.1
OR
gnubashMatch1.14.2
OR
gnubashMatch1.14.3
OR
gnubashMatch1.14.4
OR
gnubashMatch1.14.5
OR
gnubashMatch1.14.6
OR
gnubashMatch1.14.7
OR
gnubashMatch2.0
OR
gnubashMatch2.01
OR
gnubashMatch2.01.1
OR
gnubashMatch2.02
OR
gnubashMatch2.02.1
OR
gnubashMatch2.03
OR
gnubashMatch2.04
OR
gnubashMatch2.05
OR
gnubashMatch2.05a
OR
gnubashMatch2.05b
OR
gnubashMatch3.0
OR
gnubashMatch3.0.16
OR
gnubashMatch3.1
OR
gnubashMatch3.2
OR
gnubashMatch3.2.48
OR
gnubashMatch4.0
OR
gnubashMatch4.0rc1
OR
gnubashMatch4.1
OR
gnubashMatch4.2
OR
gnubashMatch4.3

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.975 High

EPSS

Percentile

100.0%