CVE-2016-10714
published 2018-02-27CVE-2016-10714: In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.17%
80.3th percentile
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | zsh | < zsh 5.3-1 (bookworm) | zsh 5.3-1 (bookworm) |
| zsh | zsh | < 5.3 | 5.3 |
| zsh | zsh | >= 0 < 5.3-1 | 5.3-1 |
| zsh | zsh | >= 0 < 5.3-1 | 5.3-1 |
| zsh | zsh | >= 0 < 5.3-1 | 5.3-1 |
| zsh | zsh | >= 0 < 5.3-1 | 5.3-1 |
| zsh | zsh | >= 0 < 5.0.2-3ubuntu6.1 | 5.0.2-3ubuntu6.1 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.1 | 5.1.1-1ubuntu2.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Zsh vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 7.8
CVE-2014-10070 [HIGH] Zsh vulnerabilities
Title: Zsh vulnerabilities
Summary: Several security issues were fixed in Zsh.
It was discovered that Zsh incorrectly handled certain enviroment variables.
An attacker could possibly use this issue to gain privileged access to the
system. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-10070)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to execute arbitrary code. This
issue only affected Ubuntu 14.04 LTS. (CVE-2014-10071)
It was discovered that Zsh incorrectly handled some symbolic links.
An attacker could possibly use this to execute arbitrary code. This issue
only affected Ubuntu 14.04 LTS. (CVE-2014-10072)
It was discovered that Zsh incorrectly handled certain errors. An attacker
could possibly use this issue to cause a den
Red Hat
zsh: Off-by-one error results in undersized buffers
vendor_redhat·2016-11-17·CVSS 9.8
CVE-2016-10714 [CRITICAL] CWE-131 zsh: Off-by-one error results in undersized buffers
zsh: Off-by-one error results in undersized buffers
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Package: zsh (Red Hat Enterprise Linux 5) - Not affected
Package: zsh (Red Hat Enterprise Linux 6) - Not affected
Package: zsh (Red Hat Enterprise Linux 7) - Not affected
Package: zsh (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2016-10714: zsh - In zsh before 5.3, an off-by-one error resulted in undersized buffers that were ...
vendor_debian·2016·CVSS 9.8
CVE-2016-10714 [CRITICAL] CVE-2016-10714: zsh - In zsh before 5.3, an off-by-one error resulted in undersized buffers that were ...
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Scope: local
bookworm: resolved (fixed in 5.3-1)
bullseye: resolved (fixed in 5.3-1)
forky: resolved (fixed in 5.3-1)
sid: resolved (fixed in 5.3-1)
trixie: resolved (fixed in 5.3-1)
GHSA
GHSA-86jf-f87h-wc84: In zsh before 5
ghsa_unreviewed·2022-05-14
CVE-2016-10714 [CRITICAL] GHSA-86jf-f87h-wc84: In zsh before 5
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
OSV
zsh vulnerabilities
osv·2018-03-08·CVSS 7.8
CVE-2014-10070 [HIGH] zsh vulnerabilities
zsh vulnerabilities
It was discovered that Zsh incorrectly handled certain enviroment variables.
An attacker could possibly use this issue to gain privileged access to the
system. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-10070)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to execute arbitrary code. This
issue only affected Ubuntu 14.04 LTS. (CVE-2014-10071)
It was discovered that Zsh incorrectly handled some symbolic links.
An attacker could possibly use this to execute arbitrary code. This issue
only affected Ubuntu 14.04 LTS. (CVE-2014-10072)
It was discovered that Zsh incorrectly handled certain errors. An attacker
could possibly use this issue to cause a denial of service. (CVE-2016-10714)
It was discovered that Zsh
OSV
CVE-2016-10714: In zsh before 5
osv·2018-02-27·CVSS 9.8
CVE-2016-10714 [CRITICAL] CVE-2016-10714: In zsh before 5
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
No detection rules found.
No public exploits indexed.
2018-02-27
Published