MGASA-2018-0168
Dashboard / Vulnerabilities / MGASA-2018-0168
MGASA-2018-0168
Summary: Updated zsh packages fix security vulnerabilities
Details: Zsh has been updated to fix 4 security issues. In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set. (CVE-2017-18205) In utils.c in zsh before 5.4, symlink expansion had a buffer overflow. (CVE-2017-18206) In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.(CVE-2018-7548) In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. (CVE-2018-7549)
References: https://advisories.mageia.org/MGASA-2018-0168.html, https://bugs.mageia.org/show_bug.cgi?id=22741, https://usn.ubuntu.com/3593-1/
Affected packages
Package
Name: zsh
Purl: pkg:rpm/mageia/zsh?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
