GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU · Bourne-Again Shell (Bash)
Date added (CISA)
2022-01-28
Remediation due
2022-07-28
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.