cbcvebase.
CVE-2021-45444
published 2022-02-14

CVE-2021-45444: In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

Affected

23 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianzsh< zsh 5.8.1-1 (bookworm)zsh 5.8.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_zsh_5.9-1_on_cbl_mariner_2.0
msrccm1_zsh_5.8.1-1_on_cbl_mariner_1.0
zshzsh< 5.8.15.8.1
zshzsh>= 0 < 5.8-6+deb11u15.8-6+deb11u1
zshzsh>= 0 < 5.8.1-15.8.1-1
zshzsh>= 0 < 5.8.1-15.8.1-1
zshzsh>= 0 < 5.8.1-15.8.1-1
zshzsh>= 0 < 5.4.2-3ubuntu3.25.4.2-3ubuntu3.2
zshzsh>= 0 < 5.8-3ubuntu1.15.8-3ubuntu1.1
zshzsh>= 0 < 5.1.1-1ubuntu2.3+esm15.1.1-1ubuntu2.3+esm1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH