CVE-2014-7186observed exploitation

CVE-2014-7186

Published · Updated

57Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 64%
from disclosure to weapon1 days
Published on NVDSep 28
1st PoC+1d
VulnCheck+1250d
exploitation probability
64%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7
none_available: Affected
Fixed
32 products (171 components)
Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux EUS (v. 5.9 server) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux Server EUS (v. 6.4) · Red Hat Enterprise Linux Server Optional (v. 6) · and others 27
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.