NULL pointer dereference in zsh - CVE-2018-7548
Published: March 7, 2018
Vulnerability identifier: #VU10873
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7548
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the subst.c source code file due to a NULL pointer dereference. A local attacker can implement ${(PA)...} characters on an empty array result, trigger a NULL pointer dereference condition and cause the service to crash.
The weakness exists in the subst.c source code file due to a NULL pointer dereference. A local attacker can implement ${(PA)...} characters on an empty array result, trigger a NULL pointer dereference condition and cause the service to crash.
Affected software
zsh
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
zsh
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
zsh
How to mitigate CVE-2018-7548
Install update from vendor's website.
zsh - addressed in versions 5.3.1-7.fc26, 5.4.1-2.fc27, 5.4.2-7.fc28