← All CVEs

CVE-2014-7187

high · 10

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

10
CVSS
58.5%
EPSS (exploit prob.)
99th
EPSS percentile
2014-09-28
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
gnubash1.14.0
gnubash1.14.1
gnubash1.14.2
gnubash1.14.3
gnubash1.14.4
gnubash1.14.5
gnubash1.14.6
gnubash1.14.7
gnubash2.0
gnubash2.01
gnubash2.01.1
gnubash2.02
gnubash2.02.1
gnubash2.03
gnubash2.04
gnubash2.05
gnubash2.05
gnubash2.05
gnubash3.0
gnubash3.0.16
gnubash3.1
gnubash3.2
gnubash3.2.48
gnubash4.0
gnubash4.0
gnubash4.1
gnubash4.2
gnubash4.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7187