Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7187

Опубликовано: 26 сент. 2014
Источник: redhat
CVSS2: 4.6

Описание

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

An off-by-one error was discovered in the way Bash was handling deeply nested flow control constructs. Depending on the layout of the .bss segment, this could allow arbitrary execution of code that would not otherwise be executed by Bash.

Отчет

Red Hat Product Security does not consider this bug to have any security impact on the bash packages shipped in Red Hat Enterprise Linux. A fix for this issue was applied as a hardening in RHSA-2014:1306, RHSA-2014:1311, and RHSA-2014:1312.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3bashNot affected
Red Hat Enterprise Linux Extended Update Support 5.6bashAffected
Red Hat Enterprise Linux 4 Extended Lifecycle SupportbashFixedRHSA-2014:131126.09.2014
Red Hat Enterprise Linux 5bashFixedRHSA-2014:130626.09.2014
Red Hat Enterprise Linux 5.6 Long LifebashFixedRHSA-2014:131126.09.2014
Red Hat Enterprise Linux 5.9 Extended Update SupportbashFixedRHSA-2014:131126.09.2014
Red Hat Enterprise Linux 6bashFixedRHSA-2014:130626.09.2014
Red Hat Enterprise Linux 6.2 Advanced Update SupportbashFixedRHSA-2014:131126.09.2014
Red Hat Enterprise Linux 6.4 Extended Update SupportbashFixedRHSA-2014:131126.09.2014
Red Hat Enterprise Linux 7bashFixedRHSA-2014:130626.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1146804bash: off-by-one error in deeply nested flow control constructs

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

nvd
больше 10 лет назад

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

debian
больше 10 лет назад

Off-by-one error in the read_token_word function in parse.y in GNU Bas ...

github
около 3 лет назад

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

fstec
больше 10 лет назад

Уязвимость интерпретатора командной строки GNU Bash, позволяющая злоумышленнику вызвать отказ в обслуживании или выполнить произвольный код

4.6 Medium

CVSS2

Уязвимость CVE-2014-7187