Rapid7

vulnerability

Oracle Linux: CVE-2018-13259: ELSA-2019-2017: zsh security and bug fix update (MODERATE)

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 4, 2018
Added
Jul 21, 2020
Modified
Dec 3, 2025

Description

An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one.
It was discovered that zsh does not properly validate the shebang of input files and it truncates it to the first 64 bytes. A local attacker may use this flaw to make zsh execute a different binary than what is expected, named with a substring of the shebang one.

Solutions

oracle-linux-upgrade-zshoracle-linux-upgrade-zsh-html
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.