CVE-2014-7187

EXPLOITED

GNU Bash through 4.3 bash43-026 - Denial of Service via Deeply Nested For Loops

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-7187 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including fdiskyou.

AI-analyzed exploit summary This exploit leverages the ShellShock vulnerability (CVE-2014-7187) in Bash via DHCP to inject arbitrary commands through environment variables. It crafts malicious DHCP responses containing payloads that trigger command execution on vulnerable systems.

Description

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

Exploits (2)

exploitdb WORKING POC VERIFIED
by fdiskyou · pythonremotelinux
https://www.exploit-db.com/exploits/36933

This exploit leverages the ShellShock vulnerability (CVE-2014-7187) in Bash via DHCP to inject arbitrary commands through environment variables. It crafts malicious DHCP responses containing payloads that trigger command execution on vulnerable systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Bash (versions vulnerable to ShellShock), DHCP clients using Bash
No auth needed
Prerequisites: Network access to DHCP traffic · Vulnerable Bash version on target · DHCP client that processes environment variables
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34860

This exploit leverages the Shellshock vulnerability (CVE-2014-7187) in Bash by crafting malicious DHCP packets with a payload in the URL option (114) to trigger remote code execution. It listens for DHCP DISCOVER broadcasts, extracts client details, and responds with malicious OFFER and ACK packets containing a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Bash (versions affected by Shellshock, e.g., 4.3.11)
No auth needed
Prerequisites: Network access to broadcast DHCP traffic · Vulnerable Bash version on target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (123)

Core 123
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577137423233&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383138121313&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142721162228379&w=2
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533593/100/0/threaded
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358026505815&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61188
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN55667175/index.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60433
Exploit mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/25/32
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383026420882&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141585637922673&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141576728022234&w=2
Vendor Advisory x_refsource_confirm
http://support.novell.com/security/cve/CVE-2014-7187.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61636
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61816
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61442
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142358078406056&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61283
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61654
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62312
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141879528318582&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1312.html
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142118135300698&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61703
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2364-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61065
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383196021590&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383081521087&w=2
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61641
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/0
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:164
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205267
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60024
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61622
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/28/10
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62343
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61565
Various Sources x_refsource_confirm
https://www.suse.com/support/shellshock/
Vendor Advisory x_refsource_confirm
http://support.apple.com/HT204244
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141450491804793&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61313
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142289270617409&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61873
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/26/2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61485
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61618
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577297623641&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383244821813&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61312
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60193
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61479
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60063
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60034
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59907
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58200
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141577241923505&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61643
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7015721
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61503
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1354.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141694386919794&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61552
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200223
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141330468527613&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61855
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60044
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61291
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141345648114150&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61287
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141383304022067&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1311.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61128
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX200217
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60055
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61550
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61633
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61328
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61129
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61603
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61857
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685749
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686084
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686479
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686445
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686131
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685914
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21687079
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686246
Various Sources x_refsource_confirm
http://www.qnap.com/i/en/support/con_show.php?cid=61
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686447
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21686494
Various Sources x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA82
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685733

Scores

EPSS 0.5846
EPSS Percentile 99.0%

Details

VulnCheck KEV 2018-03-01
CWE
CWE-119
Status published
Products (25)
gnu/bash 1.14.0
gnu/bash 1.14.1
gnu/bash 1.14.2
gnu/bash 1.14.3
gnu/bash 1.14.4
gnu/bash 1.14.5
gnu/bash 1.14.6
gnu/bash 1.14.7
gnu/bash 2.0
gnu/bash 2.01
... and 15 more
Published Sep 28, 2014
Tracked Since Feb 18, 2026