CLSA-2022-1648138003

    Dashboard / Vulnerabilities / CLSA-2022-1648138003

    CLSA-2022-1648138003

    Published: 24 Mar 2022Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2019-20044, CVE-2021-45444

    Details: * SECURITY UPDATE: Regain dropped privileges - debian/patches/CVE-2019-20044-pre.patch: change the order of the calls to setgid (this should go first) and setuid in Src/options.c. - debian/patches/CVE-2019-20044-1.patch: add extra checks to drop privileges securely in Src/options.c. - debian/patches/CVE-2019-20044-2.patch: add Src/openssh_bsd_setres_id.c and its object file to Src/zsh.mdd, fix some of the checks from the previous patch in Src/options.c, update compatibility wrappers in Src/zsh_system.h, update the uid/gid methods in AC_CHECK_FUNCS in configure.ac and add a test in Test/E01options.ztst. - debian/patches/CVE-2019-20044-3.patch: improve Src/options.c changes from above two patches. - debian/patches/CVE-2019-20044-4.patch: clean up white spaces in Src/options.c. - debian/patches/CVE-2019-20044-5.patch: add privileged tests to Test/P01privileged.ztst, remove the notes on privileged test in Test/E01options.ztst and add the prilived tests to the Test/README. - CVE-2019-20044 * SECURITY UPDATE: Arbitrary code execution - debian/patches/CVE-2021-45444.patch: save PROMPTSUBST option before the call to promptexpand() in b/Src/prompt.c and restore after it is executed. - CVE-2021-45444

    Affected packages

    Package

    Name: zsh

    Purl: pkg:deb/tuxcare/zsh?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.1.1-1ubuntu2.3+tuxcare.els1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1648138003 | CVE-DB