CVE-2014-10072Improper Restriction of Operations within the Bounds of a Memory Buffer in Project ZSH

Severity
9.8CRITICALNVD
OSV7.8
EPSS
0.4%
top 41.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMay 14

Description

In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/zsh< zsh 5.0.6-1 (bookworm)
NVDzsh_project/zsh< 5.0.6
Debianzsh/zsh< 5.0.6-1+3
Ubuntuzsh/zsh< 5.0.2-3ubuntu6.1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qgqf-33rj-w264: In utils2022-05-14
OSV
zsh vulnerabilities2018-03-08
OSV
CVE-2014-10072: In utils2018-02-27

📋Vendor Advisories

3
Ubuntu
Zsh vulnerabilities2018-03-08
Red Hat
zsh: buffer overflow when scanning very long directory paths for symbolic links2014-01-20
Debian
CVE-2014-10072: zsh - In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very lo...2014

💬Community

2
Bugzilla
CVE-2014-10072 zsh: buffer overflow when scanning very long directory paths for symbolic links2018-02-27
Bugzilla
CVE-2014-10072 zsh: buffer overflow when scanning very long directory paths for symbolic links [fedora-all]2018-02-27