SUSE-SU-2022:0733-1
Dashboard / Vulnerabilities / SUSE-SU-2022:0733-1
SUSE-SU-2022:0733-1
Summary: Security update for zsh
Details: This update for zsh fixes the following issues: - CVE-2021-45444: Fixed a vulnerability where arbitrary shell commands could be executed related to prompt expansion (bsc#1196435). - CVE-2019-20044: Fixed a vulnerability where shell privileges would not be properly dropped when unsetting the PRIVILEGED option (bsc#1163882). - CVE-2018-1100: Fixed a potential code execution via a stack-based buffer overflow in utils.c:checkmailpath() (bsc#1089030).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20220733-1/, https://bugzilla.suse.com/1089030, https://bugzilla.suse.com/1163882, https://bugzilla.suse.com/1196435, https://www.suse.com/security/cve/CVE-2018-1100, https://www.suse.com/security/cve/CVE-2019-20044, https://www.suse.com/security/cve/CVE-2021-45444
Affected packages
Package
Name: zsh
Purl: pkg:rpm/suse/zsh&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
