search menu icon-carat-right cmu-wordmark

CERT Coordination Center

GNU Bash shell executes commands in exported functions in environment variables

Vulnerability Note VU#252743

Original Release Date: 2014-09-25 | Last Revised: 2015-04-14

Overview

GNU Bash 4.3 and earlier contains a command injection vulnerability that may allow remote code execution.

Description

UPDATE: New CVE-IDs added for incomplete patches. Additional resources added and vendor patch information updated.

CWE-78: OS Command Injection

Bash supports exporting of shell functions to other instances of bash using an environment variable. This environment variable is named by the function name and starts with a "() {" as the variable value in the function definition. When Bash reaches the end of the function definition, rather than ending execution it continues to process shell commands written after the end of the function. This vulnerability is especially critical because Bash is widespread on many types of devices (UNIX-like operating systems including Linux and Mac OS X), and because many network services utilize Bash, causing the vulnerability to be network exploitable. Any service or program that sets environment variables controlled by an attacker and calls Bash may be vulnerable.

Red Hat has developed the following test:

$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

The website shellshocker.net from the health IT team at Medical Informatics Engineering has developed several tests for websites and hosts and includes update information.

This vulnerability is being actively exploited.

Impact

A malicious attacker may be able to execute arbitrary code at the privilege level of the calling application.

Solution

Apply an Update
The first several set of patches (for CVE-2014-6271) do not completely resolve the vulnerability. CVE-2014-7169, CVE-2014-6277, CVE-2014-7186, and CVE 2014-7187 identify the remaining aspects of this vulnerability. Red Hat has provided a support article with updated information and workarounds.

CERT/CC has also included vendor patch information below when notified of an update.

Vendor Information

Many UNIX-like operating systems, including Linux distributions and Apple Mac OS X include Bash and are likely to be vulnerable. Contact your vendor for information about updates or patches. This Red Hat support article and blog post describe ways that Bash can be called from other programs, including network vectors such as CGI, SSH, and DHCP. Shell Shock Exploitation Vectors describes other ways this vulnerability could be exploited.

252743
 
Affected   Unknown   Unaffected

Apple Inc.

Notified:  September 25, 2014 Updated:  October 01, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Avaya, Inc.

Notified:  September 25, 2014 Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

See the following URL for more information from the vendor.

Vendor References

Addendum

The Avaya Communications Server (CS) 1000 Rls 6 has been reported to be vulnerable.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Barracuda Networks

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Blue Coat Systems

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

CentOS

Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Check Point Software Technologies

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Cisco Systems, Inc.

Notified:  September 25, 2014 Updated:  September 26, 2014

Statement Date:   September 26, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Cygwin

Updated:  September 26, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Addendum

https://cygwin.com/ml/cygwin-announce/2014-09/msg00033.html

If you have feedback, comments, or additional information about this vulnerability, please send us email.

D-Link Systems, Inc.

Notified:  September 25, 2014 Updated:  October 07, 2014

Status

  Affected

Vendor Statement

All D-Link Devices and Software have been cleared and are not affected by this
vulnerability. All D-Link Services have been audited for the use of bash shell
implementations. Based on the results of the audit we have applied appropriate
updates, if needed, to close this potential vulnerability.  D-Link continues
to monitor CERT incase of further issues are reported about the Bash Shell.
(Edited: 10/06/2014 15:52 PST)

Vendor Information

Please contact at: security@dlink.com

Vendor References

Debian GNU/Linux

Notified:  September 25, 2014 Updated:  September 27, 2014

Statement Date:   September 25, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Dell Computer Corporation, Inc.

Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Addendum

Dell KACE systems use Bash.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Extreme Networks

Notified:  September 25, 2014 Updated:  October 01, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

F5 Networks, Inc.

Notified:  September 25, 2014 Updated:  September 26, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Fedora Project

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

FireEye

Updated:  October 02, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Fortinet, Inc.

Notified:  September 25, 2014 Updated:  September 26, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

GNU Bash

Updated:  September 25, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Gentoo Linux

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Hewlett-Packard Company

Notified:  September 25, 2014 Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

See the following URL for more information from the vendor.

Vendor References

IBM Corporation

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Addendum

AIX Toolbox for Linux Applications provides Bash and is vulnerable. IBM HTTP Server (IHS) is based on Apache and may act as an attack vector, depending on configuration.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Juniper Networks, Inc.

Notified:  September 25, 2014 Updated:  September 25, 2014

Statement Date:   September 25, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Mageia

Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

McAfee

Notified:  September 25, 2014 Updated:  October 07, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

NEC Corporation

Notified:  September 25, 2014 Updated:  October 07, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

NIKSUN

Notified:  November 10, 2014 Updated:  November 11, 2014

Status

  Affected

Vendor Statement

Information contained below is subject to change due to the evolving nature of
CVE-reported information & available fixes.

"ShellShock" CVE-2014-6271 & CVE-2014-7169 are now resolved in software patches
made available via NIKSUN SupportNet. NIKSUN has now produced software updates
for all supported product lines. We continue to observe activity on the NSON
(NIKSUN Security Observation Network) to produce current threat detections –
more signatures may be released as we continuously observe behavior globally.
Current signatures should be downloaded & installed, available via SupportNet,
to get the most out of your NIKSUN security products.

The BASH component defect affecting the community-at-large is serious, but
unlike the Heartbleed defect, which generically affected many publically
available products in exactly the same way, Shellshock requires a specific set
of conditions to exist for exploitation.

NIKSUN is both a contributor to the open source community as well as a consumer
and is leveraging those relationships to bring this issue to a satisfactory
close.

"ShellShock" CVE-2014-6271 & CVE-2014-7169 are now resolved in software patches
made available via NIKSUN SupportNet. NIKSUN has now produced software updates
for all supported product lines, with additional work in progress on breaking
CVEs related to ShellShock exposed in the last few days – software currently
in a quality assurance cycle will become available this week for remaining CVEs
associated with ShellShock now that the global community has agreed on a
sustainable, supportable fix. We continue to observe activity on the NSON
(NIKSUN Security Observation Network) to produce current threat detections with
more signatures released as we continuously observe behavior globally. Current
signatures should be downloaded & installed, available via SupportNet, to get
the most out of your NIKSUN security products.

NIKSUN is committed to providing a rapid resolution to this issue while
ensuring quality, stability & completeness of a fix.

The list below is not a fully comprehensive version list

NIKOS Appliance 4.3.2.0
NIKOS Appliance 4.3.1.2
NIKOS Appliance 4.4.1.1
NIKOS Appliance 4.4.1.2
NIKOS Appliance 4.5.0.0_9
NIKOS Appliance 4.5.0.1

NetOmni 4.3.1.2
NetOmni 4.3.2.0
NetOmni 4.4.1.1
NetOmni 4.4.1.2
NetOmni 4.5.0.0
NetOmni 4.5.0.1
NetOmni 4.5.1.0

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

NetApp

Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

See the following URL for more information from the vendor

Vendor References

Novell, Inc.

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Oracle Corporation

Notified:  September 25, 2014 Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Addendum

Solaris includes Bash and Oracle Linux is based on Red Hat Linux.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Palo Alto Networks

Notified:  September 25, 2014 Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Addendum

See PAN-SA-2012-000{2,3,4,5}. Please use CVE.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

QNAP Security

Updated:  April 14, 2015

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Red Hat, Inc.

Notified:  September 25, 2014 Updated:  September 25, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

SUSE Linux

Notified:  September 25, 2014 Updated:  September 29, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Slackware Linux Inc.

Notified:  September 25, 2014 Updated:  September 25, 2014

Statement Date:   September 25, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Sophos, Inc.

Updated:  September 27, 2014

Status

  Affected

Vendor Statement

As far as we are aware, none of Sophos's Linux or UNIX products use Bash in a way that would allow this vulnerability to be exploited with data supplied by an attacker from outside.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Trend Micro

Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Ubuntu

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

VMware

Notified:  September 25, 2014 Updated:  September 27, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Xirrus

Updated:  October 01, 2014

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

FreeBSD Project

Notified:  September 25, 2014 Updated:  September 26, 2014

Statement Date:   September 25, 2014

Status

  Not Affected

Vendor Statement

Currently we have already patched CVE-2014-6271 and CVE-2014-7169 in the FreeBSD ports tree, making it no longer vulnerable to these two issues. We will patch the new issues once the fix is validated.

The FreeBSD base system do not use bash at all and is therefore not affected.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

Addendum

FreeBSD has disabled function importing by default in the Bash port.

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Global Technology Associates, Inc.

Notified:  September 25, 2014 Updated:  October 01, 2014

Status

  Not Affected

Vendor Statement

GTA firewalls running any version of GB-OS are not vulnerable to the "shellshock" exploit.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Microsoft Corporation

Notified:  September 25, 2014 Updated:  October 10, 2014

Status

  Not Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

NetBSD

Notified:  September 25, 2014 Updated:  September 26, 2014

Status

  Not Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

ACCESS

Notified:  September 25, 2014 Updated:  September 25, 2014

Status

  Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor References

    AT&T

    Notified:  September 25, 2014 Updated:  September 25, 2014

    Status

      Unknown

    Vendor Statement

    No statement is currently available from the vendor regarding this vulnerability.

    Vendor References

      Alcatel-Lucent

      Notified:  September 25, 2014 Updated:  September 25, 2014

      Status

        Unknown

      Vendor Statement

      No statement is currently available from the vendor regarding this vulnerability.

      Vendor References

        Belkin, Inc.

        Notified:  September 25, 2014 Updated:  September 25, 2014

        Status

          Unknown

        Vendor Statement

        No statement is currently available from the vendor regarding this vulnerability.

        Vendor References

          CA Technologies

          Notified:  September 25, 2014 Updated:  September 25, 2014

          Status

            Unknown

          Vendor Statement

          No statement is currently available from the vendor regarding this vulnerability.

          Vendor References

            Cray Inc.

            Notified:  September 25, 2014 Updated:  September 25, 2014

            Status

              Unknown

            Vendor Statement

            No statement is currently available from the vendor regarding this vulnerability.

            Vendor References

              DragonFly BSD Project

              Notified:  September 25, 2014 Updated:  September 25, 2014

              Status

                Unknown

              Vendor Statement

              No statement is currently available from the vendor regarding this vulnerability.

              Vendor References

                EMC Corporation

                Notified:  September 25, 2014 Updated:  September 25, 2014

                Status

                  Unknown

                Vendor Statement

                No statement is currently available from the vendor regarding this vulnerability.

                Vendor References

                  Engarde Secure Linux

                  Notified:  September 25, 2014 Updated:  September 25, 2014

                  Status

                    Unknown

                  Vendor Statement

                  No statement is currently available from the vendor regarding this vulnerability.

                  Vendor References

                    Enterasys Networks

                    Notified:  September 25, 2014 Updated:  September 25, 2014

                    Status

                      Unknown

                    Vendor Statement

                    No statement is currently available from the vendor regarding this vulnerability.

                    Vendor References

                      Ericsson

                      Notified:  September 25, 2014 Updated:  September 25, 2014

                      Status

                        Unknown

                      Vendor Statement

                      No statement is currently available from the vendor regarding this vulnerability.

                      Vendor References

                        Force10 Networks, Inc.

                        Notified:  September 25, 2014 Updated:  September 25, 2014

                        Status

                          Unknown

                        Vendor Statement

                        No statement is currently available from the vendor regarding this vulnerability.

                        Vendor References

                          Foundry Networks, Inc.

                          Notified:  September 25, 2014 Updated:  September 25, 2014

                          Status

                            Unknown

                          Vendor Statement

                          No statement is currently available from the vendor regarding this vulnerability.

                          Vendor References

                            Fujitsu

                            Notified:  September 25, 2014 Updated:  September 25, 2014

                            Status

                              Unknown

                            Vendor Statement

                            No statement is currently available from the vendor regarding this vulnerability.

                            Vendor References

                              Google

                              Notified:  September 25, 2014 Updated:  September 25, 2014

                              Status

                                Unknown

                              Vendor Statement

                              No statement is currently available from the vendor regarding this vulnerability.

                              Vendor References

                                Hitachi

                                Notified:  September 25, 2014 Updated:  September 25, 2014

                                Status

                                  Unknown

                                Vendor Statement

                                No statement is currently available from the vendor regarding this vulnerability.

                                Vendor References

                                  IBM Corporation (zseries)

                                  Notified:  September 25, 2014 Updated:  September 25, 2014

                                  Status

                                    Unknown

                                  Vendor Statement

                                  No statement is currently available from the vendor regarding this vulnerability.

                                  Vendor References

                                    IBM eServer

                                    Notified:  September 25, 2014 Updated:  September 25, 2014

                                    Status

                                      Unknown

                                    Vendor Statement

                                    No statement is currently available from the vendor regarding this vulnerability.

                                    Vendor References

                                      Infoblox

                                      Notified:  September 25, 2014 Updated:  September 25, 2014

                                      Status

                                        Unknown

                                      Vendor Statement

                                      No statement is currently available from the vendor regarding this vulnerability.

                                      Vendor References

                                        Intel Corporation

                                        Notified:  September 25, 2014 Updated:  September 25, 2014

                                        Status

                                          Unknown

                                        Vendor Statement

                                        No statement is currently available from the vendor regarding this vulnerability.

                                        Vendor References

                                          Intoto

                                          Notified:  September 25, 2014 Updated:  September 25, 2014

                                          Status

                                            Unknown

                                          Vendor Statement

                                          No statement is currently available from the vendor regarding this vulnerability.

                                          Vendor References

                                            Mandriva S. A.

                                            Notified:  September 25, 2014 Updated:  September 25, 2014

                                            Status

                                              Unknown

                                            Vendor Statement

                                            No statement is currently available from the vendor regarding this vulnerability.

                                            Vendor References

                                              MontaVista Software, Inc.

                                              Notified:  September 25, 2014 Updated:  September 25, 2014

                                              Status

                                                Unknown

                                              Vendor Statement

                                              No statement is currently available from the vendor regarding this vulnerability.

                                              Vendor References

                                                Mozilla

                                                Notified:  October 27, 2014 Updated:  October 27, 2014

                                                Status

                                                  Unknown

                                                Vendor Statement

                                                No statement is currently available from the vendor regarding this vulnerability.

                                                Vendor References

                                                  Nokia

                                                  Notified:  September 25, 2014 Updated:  September 25, 2014

                                                  Status

                                                    Unknown

                                                  Vendor Statement

                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                  Vendor References

                                                    OpenBSD

                                                    Notified:  September 25, 2014 Updated:  September 25, 2014

                                                    Status

                                                      Unknown

                                                    Vendor Statement

                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                    Vendor References

                                                      Openwall GNU/*/Linux

                                                      Notified:  September 25, 2014 Updated:  September 25, 2014

                                                      Status

                                                        Unknown

                                                      Vendor Statement

                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                      Vendor References

                                                        Peplink

                                                        Notified:  September 25, 2014 Updated:  September 25, 2014

                                                        Status

                                                          Unknown

                                                        Vendor Statement

                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                        Vendor References

                                                          Q1 Labs

                                                          Notified:  September 25, 2014 Updated:  September 25, 2014

                                                          Status

                                                            Unknown

                                                          Vendor Statement

                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                          Vendor References

                                                            QNX Software Systems Inc.

                                                            Notified:  September 25, 2014 Updated:  September 25, 2014

                                                            Status

                                                              Unknown

                                                            Vendor Statement

                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                            Vendor References

                                                              Quagga

                                                              Notified:  September 25, 2014 Updated:  September 25, 2014

                                                              Status

                                                                Unknown

                                                              Vendor Statement

                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                              Vendor References

                                                                SafeNet

                                                                Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                Status

                                                                  Unknown

                                                                Vendor Statement

                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                Vendor References

                                                                  SmoothWall

                                                                  Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                  Status

                                                                    Unknown

                                                                  Vendor Statement

                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                  Vendor References

                                                                    Snort

                                                                    Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                    Status

                                                                      Unknown

                                                                    Vendor Statement

                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                    Vendor References

                                                                      Sony Corporation

                                                                      Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                      Status

                                                                        Unknown

                                                                      Vendor Statement

                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                      Vendor References

                                                                        Sourcefire

                                                                        Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                        Status

                                                                          Unknown

                                                                        Vendor Statement

                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                        Vendor References

                                                                          Spyrus

                                                                          Notified:  November 19, 2014 Updated:  November 19, 2014

                                                                          Status

                                                                            Unknown

                                                                          Vendor Statement

                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                          Vendor References

                                                                            Stonesoft

                                                                            Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                            Status

                                                                              Unknown

                                                                            Vendor Statement

                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                            Vendor References

                                                                              Symantec

                                                                              Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                              Status

                                                                                Unknown

                                                                              Vendor Statement

                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                              Vendor References

                                                                                The SCO Group

                                                                                Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                Status

                                                                                  Unknown

                                                                                Vendor Statement

                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                Vendor References

                                                                                  TippingPoint Technologies Inc.

                                                                                  Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                  Status

                                                                                    Unknown

                                                                                  Vendor Statement

                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                  Vendor References

                                                                                    Turbolinux

                                                                                    Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                    Status

                                                                                      Unknown

                                                                                    Vendor Statement

                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                    Vendor References

                                                                                      Unisys

                                                                                      Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                      Status

                                                                                        Unknown

                                                                                      Vendor Statement

                                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                                      Vendor References

                                                                                        Vyatta

                                                                                        Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                        Status

                                                                                          Unknown

                                                                                        Vendor Statement

                                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                                        Vendor References

                                                                                          Watchguard Technologies, Inc.

                                                                                          Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                          Status

                                                                                            Unknown

                                                                                          Vendor Statement

                                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                                          Vendor References

                                                                                            Wind River Systems, Inc.

                                                                                            Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                            Status

                                                                                              Unknown

                                                                                            Vendor Statement

                                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                                            Vendor References

                                                                                              ZyXEL

                                                                                              Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                              Status

                                                                                                Unknown

                                                                                              Vendor Statement

                                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                                              Vendor References

                                                                                                eSoft, Inc.

                                                                                                Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                                Status

                                                                                                  Unknown

                                                                                                Vendor Statement

                                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                                Vendor References

                                                                                                  m0n0wall

                                                                                                  Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                                  Status

                                                                                                    Unknown

                                                                                                  Vendor Statement

                                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                                  Vendor References

                                                                                                    netfilter

                                                                                                    Notified:  September 25, 2014 Updated:  September 25, 2014

                                                                                                    Status

                                                                                                      Unknown

                                                                                                    Vendor Statement

                                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                                    Vendor References

                                                                                                      View all 93 vendors View less vendors


                                                                                                      CVSS Metrics

                                                                                                      Group Score Vector
                                                                                                      Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C
                                                                                                      Temporal 9.5 E:H/RL:W/RC:C
                                                                                                      Environmental 9.6 CDP:LM/TD:H/CR:ND/IR:ND/AR:ND

                                                                                                      References

                                                                                                      Acknowledgements

                                                                                                      This document was written by Chris King.

                                                                                                      Other Information

                                                                                                      CVE IDs: CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, CVE-2014-7186, CVE-2014-7187
                                                                                                      Date Public: 2014-09-24
                                                                                                      Date First Published: 2014-09-25
                                                                                                      Date Last Updated: 2015-04-14 20:35 UTC
                                                                                                      Document Revision: 55

                                                                                                      Sponsored by the Department of Homeland Security Office of Cybersecurity and Communications.