
CVE-2014-6271 Shellshock: Bash RCE via Environment Variables
CVE-2014-6271, known as Shellshock, is a remote code execution vulnerability in GNU Bash where function definitions stored in environment variables execute appended commands at shell startup. Any service passing attacker-controlled data through environment variables into Bash, primarily CGI-based web applications, is exploitable without authentication via a single HTTP request. Affected an estimated 500 million systems at disclosure.
