CVE-2014-6277

EXPLOITED

GNU Bash through 4.3 bash43-026 - Remote Code Execution via Environment Variable Function Parsing

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-6277 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Michal Zalewski.

AI-analyzed exploit summary The writeup describes a vulnerability in GNU binutils' strings utility (CVE-2014-6277), where libbfd's handling of executable formats leads to an out-of-bounds crash due to insufficient range checking. The provided PoC file triggers a segmentation fault by manipulating section headers, allowing arbitrary pointer dereferencing.

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Michal Zalewski · textdoslinux
https://www.exploit-db.com/exploits/35081

The writeup describes a vulnerability in GNU binutils' strings utility (CVE-2014-6277), where libbfd's handling of executable formats leads to an out-of-bounds crash due to insufficient range checking. The provided PoC file triggers a segmentation fault by manipulating section headers, allowing arbitrary pointer dereferencing.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: GNU binutils 2.24 (strings utility)
No auth needed
Prerequisites: A maliciously crafted binary file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34860

This exploit leverages the Shellshock vulnerability (CVE-2014-6277) in Bash by crafting malicious DHCP packets with a payload in the URL option (114) to trigger remote code execution. It listens for DHCP DISCOVER broadcasts, extracts client details, and responds with malicious OFFER and ACK packets containing a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GNU Bash 4.3.11 (and other vulnerable versions)
No auth needed
Prerequisites: Network access to broadcast DHCP traffic · Vulnerable Bash version on target · Target system must process DHCP option 114
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/36933

This exploit leverages the ShellShock vulnerability (CVE-2014-6277) by injecting malicious environment variables into DHCP responses, targeting systems using vulnerable versions of Bash. It crafts DHCP Offer and ACK packets with a payload embedded in the 'dump_path' option to trigger remote command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Bash (versions affected by ShellShock)
No auth needed
Prerequisites: Network access to DHCP traffic · Vulnerable Bash version on target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (109)

Core 109
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577137423233&w=2
Various Sources x_refsource_confirm
http://linux.oracle.com/errata/ELSA-2014-3093
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142721162228379&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358026505815&w=2
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN55667175/index.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60433
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383026420882&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141585637922673&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141576728022234&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61816
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61442
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358078406056&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61283
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61654
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62312
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141879528318582&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142118135300698&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61703
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61065
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383196021590&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383081521087&w=2
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61641
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205267
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60325
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60024
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62343
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61565
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141450491804793&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61313
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142289270617409&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61485
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577297623641&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383244821813&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61312
Various Sources x_refsource_confirm
http://linux.oracle.com/errata/ELSA-2014-3094
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60193
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60063
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60034
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59907
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58200
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577241923505&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61643
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7015721
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61503
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686246
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383465822787&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61552
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61780
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200223
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141330468527613&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60044
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61291
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141345648114150&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61287
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383353622268&w=2
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383304022067&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61128
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200217
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61471
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60055
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59961
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61550
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61633
Vendor Advisory x_refsource_confirm
http://support.novell.com/security/cve/CVE-2014-6277.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61328
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685733
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61129
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61603
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61857
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686479
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686445
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21687079
Various Sources x_refsource_confirm
http://www.qnap.com/i/en/support/con_show.php?cid=61
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686494
Various Sources x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA82
Various Sources x_refsource_confirm
https://www.suse.com/support/shellshock/
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685749
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685541
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2380-1
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686131
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685914
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:164
Vendor Advisory x_refsource_confirm
http://support.apple.com/HT204244

Scores

EPSS 0.6433
EPSS Percentile 99.1%

Details

VulnCheck KEV 2018-03-01
CWE
CWE-78
Status published
Products (25)
gnu/bash 1.14.0
gnu/bash 1.14.1
gnu/bash 1.14.2
gnu/bash 1.14.3
gnu/bash 1.14.4
gnu/bash 1.14.5
gnu/bash 1.14.6
gnu/bash 1.14.7
gnu/bash 2.0
gnu/bash 2.01
... and 15 more
Published Sep 27, 2014
Tracked Since Feb 18, 2026