In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-zsh | Feb 20, 2019 | Feb 27, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-zsh | Jun 17, 2020 | Feb 27, 2018 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-zsh | Apr 16, 2020 | Feb 27, 2018 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-zsh | Dec 27, 2019 | Feb 27, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-shell-zsh-5-6-2-11-4-4-0-1-3-0 | Dec 17, 2018 | Feb 27, 2018 | |
| Suse | — | suse-upgrade-zsh | Apr 26, 2018 | Feb 27, 2018 |
| Ubuntu | ubuntu-upgrade-zsh | Apr 25, 2018 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub