CVE-2017-18206
published 2018-02-27CVE-2017-18206: In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.17%
86.7th percentile
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | zsh | < zsh 5.4.1-1 (bookworm) | zsh 5.4.1-1 (bookworm) |
| zsh | zsh | < 5.4 | 5.4 |
| zsh | zsh | >= 0 < 5.4.1-1 | 5.4.1-1 |
| zsh | zsh | >= 0 < 5.4.1-1 | 5.4.1-1 |
| zsh | zsh | >= 0 < 5.4.1-1 | 5.4.1-1 |
| zsh | zsh | >= 0 < 5.4.1-1 | 5.4.1-1 |
| zsh | zsh | >= 0 < 5.0.2-3ubuntu6.1 | 5.0.2-3ubuntu6.1 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.1 | 5.1.1-1ubuntu2.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Zsh vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 7.8
CVE-2014-10070 [HIGH] Zsh vulnerabilities
Title: Zsh vulnerabilities
Summary: Several security issues were fixed in Zsh.
It was discovered that Zsh incorrectly handled certain enviroment variables.
An attacker could possibly use this issue to gain privileged access to the
system. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-10070)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to execute arbitrary code. This
issue only affected Ubuntu 14.04 LTS. (CVE-2014-10071)
It was discovered that Zsh incorrectly handled some symbolic links.
An attacker could possibly use this to execute arbitrary code. This issue
only affected Ubuntu 14.04 LTS. (CVE-2014-10072)
It was discovered that Zsh incorrectly handled certain errors. An attacker
could possibly use this issue to cause a den
Red Hat
zsh: buffer overrun in symlinks
vendor_redhat·2017-05-09·CVSS 9.8
CVE-2017-18206 [CRITICAL] CWE-120 zsh: buffer overrun in symlinks
zsh: buffer overrun in symlinks
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
A buffer overflow flaw was found in the zsh shell symbolic link resolver. A local, unprivileged user can create a specially crafted directory path which leads to a buffer overflow in the context of the user trying to do a symbolic link resolution in the aforementioned path. If the user affected is privileged, this leads to privilege escalation.
Package: zsh (Red Hat Enterprise Linux 5) - Will not fix
Package: zsh (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2017-18206: zsh - In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
vendor_debian·2017·CVSS 9.8
CVE-2017-18206 [CRITICAL] CVE-2017-18206: zsh - In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
Scope: local
bookworm: resolved (fixed in 5.4.1-1)
bullseye: resolved (fixed in 5.4.1-1)
forky: resolved (fixed in 5.4.1-1)
sid: resolved (fixed in 5.4.1-1)
trixie: resolved (fixed in 5.4.1-1)
GHSA
GHSA-vpqc-mgq5-m5xg: In utils
ghsa_unreviewed·2022-05-13
CVE-2017-18206 [CRITICAL] CWE-119 GHSA-vpqc-mgq5-m5xg: In utils
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
OSV
zsh vulnerabilities
osv·2018-03-08·CVSS 7.8
CVE-2014-10070 [HIGH] zsh vulnerabilities
zsh vulnerabilities
It was discovered that Zsh incorrectly handled certain enviroment variables.
An attacker could possibly use this issue to gain privileged access to the
system. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-10070)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to execute arbitrary code. This
issue only affected Ubuntu 14.04 LTS. (CVE-2014-10071)
It was discovered that Zsh incorrectly handled some symbolic links.
An attacker could possibly use this to execute arbitrary code. This issue
only affected Ubuntu 14.04 LTS. (CVE-2014-10072)
It was discovered that Zsh incorrectly handled certain errors. An attacker
could possibly use this issue to cause a denial of service. (CVE-2016-10714)
It was discovered that Zsh
OSV
CVE-2017-18206: In utils
osv·2018-02-27·CVSS 9.8
CVE-2017-18206 [CRITICAL] CVE-2017-18206: In utils
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:1932https://access.redhat.com/errata/RHSA-2018:3073https://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://sourceforge.net/p/zsh/code/ci/c7a9cf465dd620ef48d586026944d9bd7a0d5d6dhttps://usn.ubuntu.com/3593-1/https://access.redhat.com/errata/RHSA-2018:1932https://access.redhat.com/errata/RHSA-2018:3073https://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://sourceforge.net/p/zsh/code/ci/c7a9cf465dd620ef48d586026944d9bd7a0d5d6dhttps://usn.ubuntu.com/3593-1/
2018-02-27
Published