zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zsh | Feb 20, 2019 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade zsh | May 2, 2018 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade zsh | May 2, 2018 | Feb 27, 2018 |
| Oracle Solaris | — | Upgrade source/demo/ksh93 to version 93.21.1.20120801-11.4.24.0.1.75.1 on Solaris 11.4Upgrade shell/ksh93 to version 93.21.1.20120801-11.4.24.0.1.75.1 on Solaris 11.4Upgrade shell/zsh to version 5.6.2-11.4.4.0.1.3.0 on Solaris 11.4Upgrade developer/astdev93 to version 93.21.1.20120801-11.4.24.0.1.75.1 on Solaris 11.4Upgrade shell/zsh to version 5.0.7-0.175.2.6.0.2.0 on Solaris 11.2 | Jun 18, 2018 | Feb 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2018 |
| Suse | — | Upgrade zsh | Apr 26, 2018 | Feb 27, 2018 |
| Ubuntu | — | Upgrade zsh | Apr 25, 2018 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub