CVE-2014-7187 is an off-by-one error in the read_token_word function of GNU Bash through version 4.3 bash43-026. This vulnerability, also known as the "word_lineno" issue, can be triggered by deeply nested for loops. It carries a critical CVSS score of 10.0, indicating a network-exploitable vulnerability with low attack complexity that can lead to a complete denial of service (application crash) and potentially other unspecified impacts, including full compromise of confidentiality, integrity, and availability. While not listed in KEV, its high EPSS and FAUCET Risk Score, along with significant community discussion and media coverage, suggest widespread awareness and potential for exploitation. Although no direct Metasploit or Nuclei exploits are listed for CVE-2014-7187 specifically, it is often discussed alongside other Shellshock-related vulnerabilities, and tools exist to test for its presence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.0CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:* | ||
1.14.3CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:* | ||
1.14.4CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.