Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18205

Опубликовано: 13 июн. 2017
Источник: redhat
CVSS3: 2
EPSS Низкий

Описание

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

A NULL pointer dereference flaw was found in the code responsible for the cd builtin command of the zsh package. An attacker could use this flaw to cause a denial of service by crashing the user shell.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5zshWill not fix
Red Hat Enterprise Linux 6zshWill not fix
Red Hat Enterprise Linux 8zshNot affected
Red Hat Enterprise Linux 7zshFixedRHSA-2018:307330.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1549862zsh: NULL dereference in cd in sh compatibility mode under given circumstances

EPSS

Процентиль: 71%
0.00671
Низкий

2 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
nvd
почти 8 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
debian
почти 8 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, th ...

CVSS3: 8.1
github
больше 3 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

oracle-oval
больше 7 лет назад

ELSA-2018-3073: zsh security and bug fix update (MODERATE)

EPSS

Процентиль: 71%
0.00671
Низкий

2 Low

CVSS3