CVE-2021-45444
published 2022-02-14CVE-2021-45444: In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.4 | 12.4 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | zsh | < zsh 5.8.1-1 (bookworm) | zsh 5.8.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_zsh_5.9-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_zsh_5.8.1-1_on_cbl_mariner_1.0 | — | — |
| zsh | zsh | < 5.8.1 | 5.8.1 |
| zsh | zsh | >= 0 < 5.8-6+deb11u1 | 5.8-6+deb11u1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.4.2-3ubuntu3.2 | 5.4.2-3ubuntu3.2 |
| zsh | zsh | >= 0 < 5.8-3ubuntu1.1 | 5.8-3ubuntu1.1 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.3+esm1 | 5.1.1-1ubuntu2.3+esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH