In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade zsh | Dec 7, 2018 | Feb 27, 2018 |
| Centos_linux | — | Upgrade zshUpgrade zsh-debuginfoUpgrade zsh-html | Aug 28, 2019 | Feb 27, 2018 |
| Debian | — | Upgrade zsh | Feb 20, 2019 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade zsh | May 2, 2018 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade zsh | May 2, 2018 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade zsh | Dec 11, 2018 | Feb 27, 2018 |
| Oracle Solaris | — | Upgrade shell/zsh to version 5.6.2-11.4.4.0.1.3.0 on Solaris 11.4 | Dec 17, 2018 | Feb 27, 2018 |
| Oracle_linux | — | Upgrade zshUpgrade zsh-html | Nov 6, 2018 | Oct 6, 2014 |
| Redhat_linux | — | Upgrade zsh-htmlUpgrade zshNo solution existsUpgrade zsh-debuginfo | Oct 31, 2018 | Feb 27, 2018 |
| Suse | — | Upgrade zsh | Apr 26, 2018 | Feb 27, 2018 |
| Ubuntu | — | Upgrade zsh | Apr 25, 2018 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub