ALT-PU-2018-2144-1
Closed vulnerabilities
BDU:2021-01390
Уязвимость функции utils.c:checkmailpath командной оболочки UNIX Zsh, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01392
Уязвимость функции exec.c:hashcmd() командной оболочки UNIX Zsh, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-1071
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
- 103359
- 103359
- RHSA-2018:3073
- RHSA-2018:3073
- https://bugzilla.redhat.com/show_bug.cgi?id=1553531
- https://bugzilla.redhat.com/show_bug.cgi?id=1553531
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1335-1] zsh security update
- [debian-lts-announce] 20180331 [SECURITY] [DLA 1335-1] zsh security update
- [debian-lts-announce] 20201201 [SECURITY] [DLA 2470-1] zsh security update
- [debian-lts-announce] 20201201 [SECURITY] [DLA 2470-1] zsh security update
- GLSA-201805-10
- GLSA-201805-10
- USN-3608-1
- USN-3608-1
Modified: 2024-11-21
CVE-2018-1100
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
- RHSA-2018:1932
- RHSA-2018:1932
- RHSA-2018:3073
- RHSA-2018:3073
- https://bugzilla.redhat.com/show_bug.cgi?id=1563395
- https://bugzilla.redhat.com/show_bug.cgi?id=1563395
- [debian-lts-announce] 20201201 [SECURITY] [DLA 2470-1] zsh security update
- [debian-lts-announce] 20201201 [SECURITY] [DLA 2470-1] zsh security update
- GLSA-201805-10
- GLSA-201805-10
- https://sourceforge.net/p/zsh/code/ci/31f72205630687c1cef89347863aab355296a27f/
- https://sourceforge.net/p/zsh/code/ci/31f72205630687c1cef89347863aab355296a27f/
- USN-3764-1
- USN-3764-1
Modified: 2024-11-21
CVE-2018-7548
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
Modified: 2024-11-21
CVE-2018-7549
In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
Closed bugs
У zsh в сборочных зависимомтях есть git-core