---
cve: "CVE-2014-6277"
severity: "LOW"
cvss: 3.1
epss: "64.3%"
vendor: "n/a"
kev: false
exploited: false
published: "2014-09-27 22:55:02"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T09:12:13+02:00"
---

# CVE-2014-6277

> 3.1 LOW · 🧪 PoC

## Beschreibung

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

## Exploit-Evidenz

- [EDB-35081 — Binary File Descriptor Library (libbfd) - Out-of-Bounds Crash](https://www.exploit-db.com/exploits/35081) ✅
- [EDB-36933 — dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)](https://www.exploit-db.com/exploits/36933) ✅
- [EDB-34860 — GNU bash 4.3.11 - Environment Variable dhclient](https://www.exploit-db.com/exploits/34860)

## Referenzen

- <http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21685749>
- <http://marc.info/?l=bugtraq&m=141577137423233&w=2>
- <https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts>
- <http://linux.oracle.com/errata/ELSA-2014-3093>
- <http://marc.info/?l=bugtraq&m=142721162228379&w=2>
- <http://marc.info/?l=bugtraq&m=142358026505815&w=2>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21686479>
- <http://jvn.jp/en/jp/JVN55667175/index.html>
- <http://secunia.com/advisories/60433>
- <http://marc.info/?l=bugtraq&m=141383026420882&w=2>
- <http://marc.info/?l=bugtraq&m=141585637922673&w=2>
- <http://marc.info/?l=bugtraq&m=141576728022234&w=2>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21685541>
- <http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2014-6277) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
