Command injection in Bash - CVE-2014-6271
Published: January 24, 2017 / Updated: August 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to incorrect parsing of environment variables. A remote attacker can execute arbitrary code on the target system as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.
Successful exploitation may allow an attacker to gain complete control over vulnerable system.
Exploitation example:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
Note: this vulnerability was being actively exploited in the wild.
Affected software
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
StoreAll OS
StoreEver ESL G3 Tape Library
Helion Public Cloud
Automation Insight
Virtualization Performance Viewer
HP Enterprise Maps
TippingPoint Next Generation Firewall
Operations Analytics
HP Business Service Automation Essentials
Operations Agent Virtual Appliance
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
Hyper-Scale Manager
StoreOnce Gen 2 Backup
Integrity SD2 CB900s i4 & i2
3PAR Service Processors
NonStop Virtual TapeServer (VTS)
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
Virtual Customer Access System (vCAS)
bash (Alpine package)
bash
FOS Firmware
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V3500
How to mitigate CVE-2014-6271
bash (Alpine package) - addressed in versions 4.2.048-r0, 4.2.049-r0
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
Hyper-Scale Manager - update to 1.5.0.59
StoreOnce Gen 2 Backup - update to 2.3.02
Integrity SD2 CB900s i4 & i2 - update to 3.8.0
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
bash - addressed in versions 4.3.22-3.fc21, 4.3.25-2.fc21
FOS Firmware - addressed in versions 6.2.2f9, 6.4.2a3, 6.4.3f3, 7.0.0d1, 7.0.2e1, 7.1.0cb, 7.1.1c1, 7.1.2b1, 7.2.0d6, 7.2.1c1
StoreAll OS - addressed in versions 6.3.4, 6.5.5
NonStop Virtual TapeServer (VTS) - addressed in versions 6.04.05, 8.3, 8.4
IBM Storwize V5000 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V3700 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V7000 - addressed in versions 7.1.0.11, 7.2.0.9
IBM Storwize V3500 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7
Virtual Customer Access System (vCAS) - update to 14.10-38402
Links to Public Exploits and PoC-codes
- Exploit #9240 - PoCs (Containing PoC's) (August 8, 2023)
- Exploit #8697 - CVE-2014-6271 (Shellshock exploit aka CVE-2014-6271) (December 26, 2022)
- Exploit #8462 - cve-2014-6271 (cve-2014-6271 (Shellshock) Bash CGI exploit/Bash binary exploit) (October 12, 2022)
- Exploit #6587 - shellshock (Shellshock exploit aka CVE-2014-6271) (July 29, 2021)
- Exploit #4681 - Qmail SMTP 1.03 - Bash Environment Variable Injection (October 8, 2020)
- Exploit #2444 - RedStar 3.0 Server - 'BEAM & RSSMON' Command Execution (Shellshock) (April 7, 2020)
- Exploit #2367 - bash-fix-exploit (Ansible role to check the CVE-2014-6271 vulnerability) (April 7, 2020)
- Exploit #2350 - exploit-CVE-2014-6271 () (April 7, 2020)
- Exploit #2276 - SwissArmyShellshocker (A multifunctional tool for checking and exploiting the Shellshock(a. k. a. Bashd00r) vulnerabilty. CVE 2014-6271. Created for Python 2.7.13.) (April 7, 2020)
- Exploit #2266 - CGIShell (shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI) (April 7, 2020)
- Exploit #2113 - shellshock-shell (A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.) (March 18, 2020)
- Exploit #2112 - RIS (CVE-2014-6271 Remote Interactive Shell - PoC Exploit) (March 18, 2020)
- Exploit #2196 - Shell-Shock (*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---) (March 18, 2020)
- Exploit #890 - GNU Bash - Environment Variable Command Injection (Metasploit) (March 18, 2020)
- Exploit #1845 - Advantech Switch Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #1830 - IPFire Bash Environment Variable Injection (Shellshock) (March 18, 2020)
- Exploit #1782 - Pure-FTPd External Authentication Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #1781 - Apache mod_cgi Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #1777 - CUPS Filter Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #1746 - OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock) (March 18, 2020)
- Exploit #1744 - Dhclient Bash Environment Variable Injection (Shellshock) (March 18, 2020)
- Exploit #1734 - Qmail SMTP Bash Environment Variable Injection (Shellshock) (March 18, 2020)
- Exploit #892 - GNU Bash - Environment Variable Command Injection (Shellshock) (March 18, 2020)
- Exploit #891 - Bash - Environment Variables Code Injection (Shellshock) (March 18, 2020)
- Exploit #879 - TrendMicro InterScan Web Security Virtual Appliance - Remote Code Execution (Shellshock) (March 18, 2020)
- Exploit #38 - Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner (March 18, 2020)
- Exploit #120 - puppet-shellshock (This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible) (March 18, 2020)
- Exploit #121 - exploit-CVE-2014-6271 (Shellshock exploit + vulnerable environment) (March 18, 2020)
- Exploit #122 - CVE-2014-6271 (Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.) (March 18, 2020)
- Exploit #123 - CVE-in-Ruby (Exploits written & ported to Ruby - no Metasploit) (March 18, 2020)
- Exploit #873 - Qmail SMTP - Bash Environment Variable Injection (Metasploit) (March 18, 2020)
- Exploit #874 - Cisco Unified Communications Manager - Multiple Vulnerabilities (March 18, 2020)
- Exploit #875 - Kemp Load Master 7.1.16 - Multiple Vulnerabilities (March 18, 2020)
- Exploit #876 - PHP < 5.6.2 - Bypass disable_functions Exploit (Shellshock) (March 18, 2020)
- Exploit #877 - Bash CGI - Remote Code Execution (Shellshock) (Metasploit) (March 18, 2020)
- Exploit #878 - IPFire - Cgi Web Interface Authenticated Bash Environment Variable Code Injection (March 18, 2020)
- Exploit #37 - DHCP Client Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #880 - IPFire - Bash Environment Variable Injection (Shellshock) (Metasploit) (March 18, 2020)
- Exploit #881 - Advantech Switch - Bash Environment Variable Code Injection (Shellshock) (Metasploit) (March 18, 2020)
- Exploit #882 - QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit) (March 18, 2020)
- Exploit #883 - QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit) (March 18, 2020)
- Exploit #884 - CUPS Filter - Bash Environment Variable Code Injection (Metasploit) (March 18, 2020)
- Exploit #885 - Apache mod_cgi - Remote Exploit (Shellshock) (March 18, 2020)
- Exploit #886 - Postfix SMTP 4.2.x < 4.2.48 - Remote Exploit (Shellshock) (March 18, 2020)
- Exploit #887 - OpenVPN 2.2.29 - Remote Exploit (Shellshock) (March 18, 2020)
- Exploit #888 - Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit) (March 18, 2020)
- Exploit #889 - GNU bash 4.3.11 - Environment Variable dhclient Exploit (March 18, 2020)
External References
Related Security Bulletins
- Multiple RCE vulnerabilities in GNU Bash aka Shellshock
- Ubuntu update for Bash
- Debian update for bash
- Debian update for bash
- Gentoo update for Bash
- Gentoo update for Bash
- Slackware Linux update for bash
- Slackware Linux update for bash
- openSUSE update for bash
- openSUSE update for bash
- SUSE Linux update for bash
- openSUSE update for bash
- SUSE Linux update for bash
- openSUSE update for bash
- openSUSE update for bash
- openSUSE update for bash
- SUSE Linux update for bash
- SUSE Linux update for Containment-Studio
- openSUSE update for Shellshock
- Amazon Linux AMI update for bash
- Amazon Linux AMI update for bash
- Red Hat update for bash
- Red Hat update for bash
- Command injection in bash (Alpine package)
- SUSE Linux update for bash
- SUSE Linux update for bash
- SUSE Linux update for bash
- Multiple vulnerabilities in IBM FlashSystem 840 and V840
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in HP Remote Device Access: Virtual Customer Access System (vCAS)
- Multiple vulnerabilities in HP Automation Insight
- Multiple vulnerabilities in HP Business Service Automation Essentials
- Multiple vulnerabilities in HP Operations Analytics
- Multiple vulnerabilities in HP Next Generation Firewall (NGFW)
- Multiple vulnerabilities in HP Integrity SD2 CB900s i4 & i2
- Multiple vulnerabilities in HP Operation Agent Virtual Appliance
- Multiple vulnerabilities in HP Virtualization Performance Viewer
- Multiple vulnerabilities in HP Helion Public Cloud
- Multiple vulnerabilities in HP Enterprise Maps Virtual Appliance
- Multiple vulnerabilities in HP NonStop Virtual TapeServer (VTS)
- Multiple vulnerabilities in HP 3PAR Service Processor (SP)
- Multiple vulnerabilities in HP StoreOnce Gen 2 Backup
- Multiple vulnerabilities in HP StoreEver ESL G3 Tape Library
- Multiple vulnerabilities in HP StoreAll Operating System
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Multiple vulnerabilities in IBM ProtecTIER
- Multiple vulnerabilities in IBM Hyper-Scale Manager
- Fedora 21 update for bash
- Fedora 21 update for bash