CVE-2018-1071
published 2018-03-09CVE-2018-1071: zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.43%
35.4th percentile
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | zsh | < zsh 5.4.2-4 (bookworm) | zsh 5.4.2-4 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| zsh | zsh | <= 5.4.2 | — |
| zsh | zsh | — | — |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.0.2-3ubuntu6.2 | 5.0.2-3ubuntu6.2 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.2 | 5.1.1-1ubuntu2.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Zsh vulnerabilities
vendor_ubuntu·2018-03-27·CVSS 5.5
CVE-2018-1071 [MEDIUM] Zsh vulnerabilities
Title: Zsh vulnerabilities
Summary: Several security issues were fixed in Zsh.
Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service. (CVE-2018-1071)
It was discovered that Zsh incorrectly handled certain files. An attacker could
possibly use this to execute arbitrary code. (CVE-2018-1083)
Instructions: After a standard system update you need to restart Zsh to make
all the necessary changes
Red Hat
zsh: Stack-based buffer overflow in exec.c:hashcmd()
vendor_redhat·2018-03-09·CVSS 5.5
CVE-2018-1071 [MEDIUM] CWE-121 zsh: Stack-based buffer overflow in exec.c:hashcmd()
zsh: Stack-based buffer overflow in exec.c:hashcmd()
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
Package: zsh (Red Hat Enterprise Linux 5) - Will not fix
Package: zsh (Red Hat Enterprise Linux 6) - Will not fix
Package: zsh (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1071: zsh - zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the ...
vendor_debian·2018·CVSS 5.5
CVE-2018-1071 [MEDIUM] CVE-2018-1071: zsh - zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the ...
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 5.4.2-4)
bullseye: resolved (fixed in 5.4.2-4)
forky: resolved (fixed in 5.4.2-4)
sid: resolved (fixed in 5.4.2-4)
trixie: resolved (fixed in 5.4.2-4)
GHSA
GHSA-xc49-qj7m-vpp4: zsh through version 5
ghsa_unreviewed·2022-05-13
CVE-2018-1071 [MEDIUM] CWE-121 GHSA-xc49-qj7m-vpp4: zsh through version 5
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
OSV
zsh vulnerabilities
osv·2018-03-27·CVSS 5.5
CVE-2018-1071 [MEDIUM] zsh vulnerabilities
zsh vulnerabilities
Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service. (CVE-2018-1071)
It was discovered that Zsh incorrectly handled certain files. An attacker could
possibly use this to execute arbitrary code. (CVE-2018-1083)
OSV
CVE-2018-1071: zsh through version 5
osv·2018-03-09·CVSS 5.5
CVE-2018-1071 [MEDIUM] CVE-2018-1071: zsh through version 5
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1999046 jenkins: Unauthorized users could access agent logs
bugzilla·2018-08-23·CVSS 4.3
CVE-2018-1999046 [MEDIUM] CVE-2018-1999046 jenkins: Unauthorized users could access agent logs
CVE-2018-1999046 jenkins: Unauthorized users could access agent logs
Jenkins before LTS version 2.121.3 and weekly version 2.138 allow unauthorized users to access agent logs.
Users with Overall/Read permission were able to access the URL serving agent logs on the UI due to a lack of permission checks.
Access to the affected URL is now limited to users with the correct Agent/Connect permission.
External Reference:
https://jenkins.io/security/advisory/2018-08-15/#SECURITY-1071
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1620352]
---
Upstream commit: https://github.com/jenkinsci/jenkins/commit/6867e4469525d16319b1bae9c840b933fe4e23c4
---
By default Jenkins doesn't setup users without the Agent/Connect permission. It's possible to setup such
Bugzilla
CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd() [fedora-all]
bugzilla·2018-03-09·CVSS 5.5
CVE-2018-1071 [MEDIUM] CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd() [fedora-all]
CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd()
bugzilla·2018-03-09·CVSS 5.5
CVE-2018-1071 [MEDIUM] CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd()
CVE-2018-1071 zsh: Stack-based buffer overflow in exec.c:hashcmd()
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
Discussion:
Acknowledgments:
Name: Richard Maciel Costa (Red Hat)
---
Created zsh tracking bugs for this issue:
Affects: fedora-all [bug 1553533]
---
Do we have a reproducer and/or fix for this bug?
"a stack-based buffer overflow in the exec.c:hashcmd() function" is too vague and I was not able to find any publicly available information about CVE-2018-1071).
---
(In reply to Kamil Dudka from comment #3)
> Do we have a reproducer and/or fix for this bug?
>
> "a stack-based buffer overflow in the exec.c:hashcmd() function" is too
> vague and I
http://www.securityfocus.com/bid/103359https://access.redhat.com/errata/RHSA-2018:3073https://bugzilla.redhat.com/show_bug.cgi?id=1553531https://lists.debian.org/debian-lts-announce/2018/03/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://usn.ubuntu.com/3608-1/http://www.securityfocus.com/bid/103359https://access.redhat.com/errata/RHSA-2018:3073https://bugzilla.redhat.com/show_bug.cgi?id=1553531https://lists.debian.org/debian-lts-announce/2018/03/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://usn.ubuntu.com/3608-1/
2018-03-09
Published