CVE-2014-7186

EXPLOITED

GNU Bash <4.3 - DoS

Title source: llm

Description

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.

Exploits (2)

exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34860
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/36933

References (125)

... and 105 more

Scores

EPSS 0.8935
EPSS Percentile 99.5%

Details

VulnCheck KEV 2018-03-01
CWE
CWE-119
Status published
Products (25)
gnu/bash 1.14.0
gnu/bash 1.14.1
gnu/bash 1.14.2
gnu/bash 1.14.3
gnu/bash 1.14.4
gnu/bash 1.14.5
gnu/bash 1.14.6
gnu/bash 1.14.7
gnu/bash 2.0
gnu/bash 2.01
... and 15 more
Published Sep 28, 2014
Tracked Since Feb 18, 2026