CVE-2017-18205NULL Pointer Dereference in Project ZSH

Severity
8.1HIGHNVD
OSV7.8
EPSS
0.7%
top 28.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMay 14

Description

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

debiandebian/zsh< zsh 5.4.1-1 (bookworm)
NVDzsh_project/zsh< 5.4
Debianzsh/zsh< 5.4.1-1+3
Ubuntuzsh/zsh< 5.0.2-3ubuntu6.1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-r2ph-r5g8-q5vv: In builtin2022-05-14
OSV
zsh vulnerabilities2018-03-08
OSV
CVE-2017-18205: In builtin2018-02-27

📋Vendor Advisories

3
Ubuntu
Zsh vulnerabilities2018-03-08
Red Hat
zsh: NULL dereference in cd in sh compatibility mode under given circumstances2017-06-13
Debian
CVE-2017-18205: zsh - In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a N...2017

💬Community

1
Bugzilla
CVE-2017-18205 zsh: NULL dereference in cd in sh compatibility mode under given circumstances2018-02-27