mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
2.3 KiB
2.3 KiB
CVE-2014-7187
Description
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
POC
Reference
- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733
- http://www.qnap.com/i/en/support/con_show.php?cid=61
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183
Github
- https://github.com/9069332997/session-1-full-stack
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CyberlearnbyVK/redteam-notebook
- https://github.com/EvanK/shocktrooper
- https://github.com/HttpEduardo/ShellTHEbest
- https://github.com/MrCl0wnLab/ShellShockHunter
- https://github.com/Parist0nH1ll/Vulnerabilities-Write-Ups
- https://github.com/SaltwaterC/sploit-tools
- https://github.com/UMDTERPS/Shell-Shock-Update
- https://github.com/ankh2054/linux-pentest
- https://github.com/demining/ShellShock-Attack
- https://github.com/dokku-alt/dokku-alt
- https://github.com/eduardo-paim/ShellTHEbest
- https://github.com/ericlake/fabric-shellshock
- https://github.com/foobarto/redteam-notebook
- https://github.com/giterlizzi/secdb-feeds
- https://github.com/googleinurl/Xpl-SHELLSHOCK-Ch3ck
- https://github.com/hannob/bashcheck
- https://github.com/httpEduardo/ShellTHEbest
- https://github.com/inspirion87/w-test
- https://github.com/jdauphant/patch-bash-shellshock
- https://github.com/meherarfaoui09/meher
- https://github.com/mubix/shellshocker-pocs
- https://github.com/opragel/shellshockFixOSX
- https://github.com/readloud/ShellShockHunter-v1.0
- https://github.com/trhacknon/Xpl-SHELLSHOCK-Ch3ck
- https://github.com/xdistro/ShellShock