In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zsh | Feb 20, 2019 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade zsh | Jun 17, 2020 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade zsh | Apr 16, 2020 | Feb 27, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade zsh | Dec 27, 2019 | Feb 27, 2018 |
| Oracle Solaris | — | Upgrade shell/zsh to version 5.6.2-11.4.4.0.1.3.0 on Solaris 11.4 | Dec 17, 2018 | Feb 27, 2018 |
| Suse | — | Upgrade zsh | Apr 26, 2018 | Feb 27, 2018 |
| Ubuntu | — | Upgrade zsh | Apr 25, 2018 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub