Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-10071

Опубликовано: 06 окт. 2014
Источник: redhat
CVSS3: 2.8

Описание

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

A buffer overflow flaw was found in the zsh shell file descriptor redirection functionality. An attacker could use this flaw to cause a denial of service by crashing the user shell.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5zshWill not fix
Red Hat Enterprise Linux 6zshWill not fix
Red Hat Enterprise Linux 8zshNot affected
Red Hat Enterprise Linux 7zshFixedRHSA-2018:307330.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120->CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1549855zsh: buffer overflow for very long fds in >& fd syntax

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

CVSS3: 9.8
nvd
почти 8 лет назад

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

CVSS3: 9.8
debian
почти 8 лет назад

In exec.c in zsh before 5.0.7, there is a buffer overflow for very lon ...

CVSS3: 9.8
github
больше 3 лет назад

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

oracle-oval
больше 7 лет назад

ELSA-2018-3073: zsh security and bug fix update (MODERATE)

2.8 Low

CVSS3