Top 10 winner
ShellShock
CVE - CVE-2014-6271
Shellshock: GNU Bash through 4.3 keeps executing text that trails a function definition stored in an environment variable. Any path that carries attacker-controlled data into the environment across a privilege boundary, such as Apache mod_cgi, OpenSSH ForceCommand or DHCP clients, therefore yields remote command execution.
Record
- Document
- CVE - CVE-2014-6271
- Published by
- cve.mitre.org
- Format
- Advisory
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of cve.mitre.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .