CVE-2018-1083

Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.

Published : 2018-03-28 13:29 Updated : 2019-10-09 23:38

7.2
CVSS Score More info
Score 7.2 / 10
7.2
Vendor Product Version URI
Canonical Ubuntu Linux 14.04 cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~
Canonical Ubuntu Linux 16.04 cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
Canonical Ubuntu Linux 17.10 cpe:/o:canonical:ubuntu_linux:17.10
Debian Debian Linux 7.0 cpe:/o:debian:debian_linux:7.0
Zsh Zsh 5.4.1 cpe:/a:zsh:zsh:5.4.1
Redhat Enterprise Linux Desktop 6.0 cpe:/o:redhat:enterprise_linux_desktop:6.0
Redhat Enterprise Linux Desktop 7.0 cpe:/o:redhat:enterprise_linux_desktop:7.0
Redhat Enterprise Linux Server 6.0 cpe:/o:redhat:enterprise_linux_server:6.0
Redhat Enterprise Linux Server 7.0 cpe:/o:redhat:enterprise_linux_server:7.0
Redhat Enterprise Linux Workstation 6.0 cpe:/o:redhat:enterprise_linux_workstation:6.0
Redhat Enterprise Linux Workstation 7.0 cpe:/o:redhat:enterprise_linux_workstation:7.0
  1. Canonical (1) Search CVE
    1. Ubuntu Linux (3) Search CVE
      1. 14.04
      2. 16.04
      3. 17.10
  2. Redhat (3) Search CVE
    1. Enterprise Linux Desktop (2) Search CVE
      1. 6.0
      2. 7.0
    2. Enterprise Linux Workstation (2) Search CVE
      1. 6.0
      2. 7.0
    3. Enterprise Linux Server (2) Search CVE
      1. 6.0
      2. 7.0
  3. Debian (1) Search CVE
    1. Debian Linux (1) Search CVE
      1. 7.0
  4. Zsh (1) Search CVE
    1. Zsh (1) Search CVE
      1. 5.4.1

CWE

ID Name Description Links
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer. CVE

History of changes

Date Event
2019-03-20 13:59
2018-10-31 10:30
2018-10-21 10:29
2018-06-20 01:29
2018-04-24 12:53
2018-04-04 01:29
2018-04-02 01:29
2018-03-30 01:29
2018-03-28 13:29

New CVE