CVE-2018-1083
published 2018-03-28CVE-2018-1083: Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
46.5th percentile
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | zsh | < zsh 5.4.2-4 (bookworm) | zsh 5.4.2-4 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| zsh | zsh | <= 5.4.1 | — |
| zsh | zsh | — | — |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.4.2-4 | 5.4.2-4 |
| zsh | zsh | >= 0 < 5.0.2-3ubuntu6.2 | 5.0.2-3ubuntu6.2 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.2 | 5.1.1-1ubuntu2.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqpc-3fmx-3wqw: Zsh before version 5
ghsa_unreviewed·2022-05-13
CVE-2018-1083 [HIGH] CWE-119 GHSA-pqpc-3fmx-3wqw: Zsh before version 5
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
OSV
CVE-2018-1083: Zsh before version 5
osv·2018-03-28·CVSS 7.8
CVE-2018-1083 [HIGH] CVE-2018-1083: Zsh before version 5
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
OSV
zsh vulnerabilities
osv·2018-03-27·CVSS 5.5
CVE-2018-1071 [MEDIUM] zsh vulnerabilities
zsh vulnerabilities
Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service. (CVE-2018-1071)
It was discovered that Zsh incorrectly handled certain files. An attacker could
possibly use this to execute arbitrary code. (CVE-2018-1083)
Ubuntu
Zsh vulnerabilities
vendor_ubuntu·2018-03-27·CVSS 5.5
CVE-2018-1071 [MEDIUM] Zsh vulnerabilities
Title: Zsh vulnerabilities
Summary: Several security issues were fixed in Zsh.
Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this to cause a denial of service. (CVE-2018-1071)
It was discovered that Zsh incorrectly handled certain files. An attacker could
possibly use this to execute arbitrary code. (CVE-2018-1083)
Instructions: After a standard system update you need to restart Zsh to make
all the necessary changes
Red Hat
zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
vendor_redhat·2018-03-26·CVSS 7.8
CVE-2018-1083 [HIGH] CWE-120 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
A buffer overflow flaw was found in the zsh shell auto-complete functionality. A local, unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use auto-complete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
Debian
CVE-2018-1083: zsh - Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell ...
vendor_debian·2018·CVSS 7.8
CVE-2018-1083 [HIGH] CVE-2018-1083: zsh - Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell ...
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
Scope: local
bookworm: resolved (fixed in 5.4.2-4)
bullseye: resolved (fixed in 5.4.2-4)
forky: resolved (fixed in 5.4.2-4)
sid: resolved (fixed in 5.4.2-4)
trixie: resolved (fixed in 5.4.2-4)
No detection rules found.
Bugzilla
CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c [fedora-all]
bugzilla·2018-03-26·CVSS 7.8
CVE-2018-1083 [HIGH] CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c [fedora-all]
CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
bugzilla·2018-03-16·CVSS 7.8
CVE-2018-1083 [HIGH] CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c
zsh is vulnerable to a stack-based buffer overflow in the gen_matches_files() function. A local attacker could exploit this through tab completion of directories with long names leading to arbitrary code execution.
Discussion:
Upstream Patch:
https://sourceforge.net/p/zsh/code/ci/259ac472eac291c8c103c7a0d8a4eaf3c2942ed7
---
Created zsh tracking bugs for this issue:
Affects: fedora-all [bug 1560696]
---
Acknowledgments:
Name: Richard Maciel Costa (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1932 https://access.redhat.com/errata/RHSA-2018:1932
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
http://www.securityfocus.com/bid/103572https://access.redhat.com/errata/RHSA-2018:1932https://access.redhat.com/errata/RHSA-2018:3073https://bugzilla.redhat.com/show_bug.cgi?id=1557382https://lists.debian.org/debian-lts-announce/2018/03/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://sourceforge.net/p/zsh/code/ci/259ac472eac291c8c103c7a0d8a4eaf3c2942ed7https://usn.ubuntu.com/3608-1/http://www.securityfocus.com/bid/103572https://access.redhat.com/errata/RHSA-2018:1932https://access.redhat.com/errata/RHSA-2018:3073https://bugzilla.redhat.com/show_bug.cgi?id=1557382https://lists.debian.org/debian-lts-announce/2018/03/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlhttps://security.gentoo.org/glsa/201805-10https://sourceforge.net/p/zsh/code/ci/259ac472eac291c8c103c7a0d8a4eaf3c2942ed7https://usn.ubuntu.com/3608-1/
2018-03-28
Published