CVE-2014-7187
EXPLOITEDGNU Bash <4.3 - DoS
Title source: llmDescription
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by fdiskyou · pythonremotelinux
https://www.exploit-db.com/exploits/36933
References (123)
... and 103 more
Scores
EPSS
0.9061
EPSS Percentile
99.6%
Exploitation Intel
VulnCheck KEV
2018-03-01
Classification
CWE
CWE-119
Status
draft
Affected Products (28)
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
gnu/bash
... and 13 more
Timeline
Published
Sep 28, 2014
Tracked Since
Feb 18, 2026