Stack-based buffer overflow in zsh - CVE-2018-1100

 

Stack-based buffer overflow in zsh - CVE-2018-1100

Published: April 11, 2018 / Updated: April 12, 2018


Vulnerability identifier: #VU11771
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1100
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker can trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

zsh
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
Opensuse
Fedora
zsh
zsh-debuginfo
zsh-debugsource

How to mitigate CVE-2018-1100

Install update from vendor's website.

zsh - update to 5.0.5-6.19.1
zsh-debuginfo - update to 5.0.5-6.19.1
zsh-debugsource - update to 5.0.5-6.19.1
zsh - addressed in versions 5.4.1-3.fc27, 5.5-1.fc28

External References

Related Security Bulletins