SUSE-SU-2018:2686-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2686-1
SUSE-SU-2018:2686-1
Summary: Security update for zsh
Details: This update for zsh to version 5.6 fixes the following security issues: - CVE-2018-0502: The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line (bsc#1107296). - CVE-2018-13259: Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one (bsc#1107294).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182686-1/, https://bugzilla.suse.com/1107294, https://bugzilla.suse.com/1107296, https://www.suse.com/security/cve/CVE-2018-0502, https://www.suse.com/security/cve/CVE-2018-13259
Affected packages
Package
Name: zsh
Purl: pkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
