← All CVEs

CVE-2014-7186

high · 10

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.

10
CVSS
64.3%
EPSS (exploit prob.)
99th
EPSS percentile
2014-09-28
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
gnubash1.14.0
gnubash1.14.1
gnubash1.14.2
gnubash1.14.3
gnubash1.14.4
gnubash1.14.5
gnubash1.14.6
gnubash1.14.7
gnubash2.0
gnubash2.01
gnubash2.01.1
gnubash2.02
gnubash2.02.1
gnubash2.03
gnubash2.04
gnubash2.05
gnubash2.05
gnubash2.05
gnubash3.0
gnubash3.0.16
gnubash3.1
gnubash3.2
gnubash3.2.48
gnubash4.0
gnubash4.0
gnubash4.1
gnubash4.2
gnubash4.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7186