Stack-based buffer overflow in zsh - CVE-2018-1100
Published: April 11, 2018 / Updated: April 12, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker can trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
Opensuse
Fedora
zsh
zsh-debuginfo
zsh-debugsource
How to mitigate CVE-2018-1100
zsh-debuginfo - update to 5.0.5-6.19.1
zsh-debugsource - update to 5.0.5-6.19.1
zsh - addressed in versions 5.4.1-3.fc27, 5.5-1.fc28
External References
Related Security Bulletins
- Arch Linux update for zsh
- Gentoo update for Zsh
- Red Hat update for zsh
- Red Hat update for zsh
- OpenSUSE Linux update for zsh
- OpenSUSE Linux update for zsh
- Amazon Linux AMI update for zsh
- Slackware Linux update for zsh
- Red Hat update for zsh
- SUSE update for zsh
- Fedora 28 update for zsh
- Fedora 27 update for zsh