« List of all CVEs

CVE-2014-7187

Published: 9/28/2014 Last updated: 8/6/2024 Reserved: 9/25/2014

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-bash

Products affected (1)

Product Vendor Version
n/a n/a Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016.

References (258)