CVE-2014-7186

EXPLOITED

GNU Bash through 4.3 - Denial of Service via Redirection Here Document Handling

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-7186 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits.

AI-analyzed exploit summary This exploit leverages the Shellshock vulnerability (CVE-2014-7186) in Bash by crafting malicious DHCP packets. It listens for DHCP DISCOVER broadcasts, extracts client details, and responds with an OFFER and ACK containing a malicious payload in the URL option (114), triggering remote code execution.

Description

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.

Exploits (2)

exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34860

This exploit leverages the Shellshock vulnerability (CVE-2014-7186) in Bash by crafting malicious DHCP packets. It listens for DHCP DISCOVER broadcasts, extracts client details, and responds with an OFFER and ACK containing a malicious payload in the URL option (114), triggering remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Bash (versions affected by Shellshock, e.g., 4.3.11)
No auth needed
Prerequisites: Network access to broadcast DHCP traffic · Vulnerable Bash version on target
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/36933

This exploit leverages the ShellShock vulnerability (CVE-2014-7186) by injecting malicious environment variables into DHCP responses. It crafts DHCP OFFER and ACK packets with a payload in the 'dump_path' option, which is processed by the victim's bash shell via dhclient.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Bash (via dhclient)
No auth needed
Prerequisites: Network access to DHCP client · Vulnerable version of Bash · dhclient in use
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (125)

Core 125
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577137423233&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142721162228379&w=2
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533593/100/0/threaded
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358026505815&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61188
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN55667175/index.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60433
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/25/32
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383026420882&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141585637922673&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141576728022234&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61636
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61816
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61442
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358078406056&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61283
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142113462216480&w=2
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61654
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62312
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141879528318582&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1312.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142118135300698&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61703
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61065
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383196021590&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383081521087&w=2
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61641
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/0
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60024
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61622
Vendor Advisory x_refsource_confirm
http://support.novell.com/security/cve/CVE-2014-7186.html
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/28/10
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62343
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61565
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141450491804793&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61313
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142289270617409&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61873
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/26/2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61485
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61618
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577297623641&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383244821813&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61312
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60193
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61479
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60063
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60034
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59907
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58200
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577241923505&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61643
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7015721
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61503
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686246
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1354.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141694386919794&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61552
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61780
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200223
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62228
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141330468527613&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60044
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61291
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141345648114150&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61287
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61711
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383304022067&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1311.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61128
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200217
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61471
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60055
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61550
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61633
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61328
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685733
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61129
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61603
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686479
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686445
Various Sources x_refsource_confirm
https://www.suse.com/support/shellshock/
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21687079
Various Sources x_refsource_confirm
http://www.qnap.com/i/en/support/con_show.php?cid=61
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686447
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686494
Various Sources x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA82
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383138121313&w=2
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685749
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686084
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685541
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2364-1
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686131
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685914
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:164
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205267
Vendor Advisory x_refsource_confirm
http://support.apple.com/HT204244

Scores

EPSS 0.6434
EPSS Percentile 99.1%

Details

VulnCheck KEV 2018-03-01
CWE
CWE-119
Status published
Products (25)
gnu/bash 1.14.0
gnu/bash 1.14.1
gnu/bash 1.14.2
gnu/bash 1.14.3
gnu/bash 1.14.4
gnu/bash 1.14.5
gnu/bash 1.14.6
gnu/bash 1.14.7
gnu/bash 2.0
gnu/bash 2.01
... and 15 more
Published Sep 28, 2014
Tracked Since Feb 18, 2026