Off-by-one error in Bash - CVE-2014-7187
Published: January 24, 2017 / Updated: March 11, 2017
Vulnerability details
The weakness exists due to off-by-one-error when handling deeply nested flow control constructs. A remote attacker can trigger memory corruption and execute arbitrary code with privileges of the current user.
Exploitation example:
(for x in {1..200} ; do echo "for x$x in ; do :"; done; for x in {1..200} ; do echo done ; done) | bash ||
echo "CVE-2014-7187 vulnerable, word_lineno"
Successful exploitation results in arbitrary code execution on the vulnerable system.
Note: this vulnerability was being actively exploited.
Affected software
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
StoreEver ESL G3 Tape Library
Automation Insight
Virtualization Performance Viewer
TippingPoint Next Generation Firewall
Operations Analytics
HP Business Service Automation Essentials
Operations Agent Virtual Appliance
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem V840 9846-AE1 & 9848-AE1
Hyper-Scale Manager
StoreOnce Gen 2 Backup
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
bash (Alpine package)
HP Systems Insight Manager
FOS Firmware
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3500
How to mitigate CVE-2014-7187
bash (Alpine package) - update to 4.2.051-r0
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
Hyper-Scale Manager - update to 1.5.0.59
StoreOnce Gen 2 Backup - update to 2.3.02
FOS Firmware - addressed in versions 6.2.2f9, 6.4.2a3, 6.4.3f3, 7.0.0d1, 7.0.2e1, 7.1.0cb, 7.1.1c1, 7.1.2b1, 7.2.0d6, 7.2.1c1
IBM Storwize V3700 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V7000 - addressed in versions 7.1.0.11, 7.2.0.9
IBM Storwize V5000 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V3500 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple RCE vulnerabilities in GNU Bash aka Shellshock
- Ubuntu update for Bash
- Gentoo update for Bash
- openSUSE update for bash
- SUSE Linux update for bash
- openSUSE update for bash
- SUSE Linux update for bash
- openSUSE update for bash
- openSUSE update for bash
- openSUSE update for Shellshock
- Amazon Linux AMI update for bash
- Red Hat update for bash
- Off-by-one error in bash (Alpine package)
- Multiple vulnerabilities in IBM FlashSystem 840 and V840
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in HP Automation Insight
- Multiple vulnerabilities in HP Business Service Automation Essentials
- Multiple vulnerabilities in HP Operations Analytics
- Multiple vulnerabilities in HP Next Generation Firewall (NGFW)
- Multiple vulnerabilities in HP Systems Insight Manager for Windows
- Multiple vulnerabilities in HP Operation Agent Virtual Appliance
- Multiple vulnerabilities in HP Virtualization Performance Viewer
- Multiple vulnerabilities in HP StoreOnce Gen 2 Backup
- Multiple vulnerabilities in HP StoreEver ESL G3 Tape Library
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Multiple vulnerabilities in IBM ProtecTIER
- Multiple vulnerabilities in IBM Hyper-Scale Manager