Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18205

Опубликовано: 13 июн. 2017
Источник: redhat
CVSS3: 2

Описание

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

A NULL pointer dereference flaw was found in the code responsible for the cd builtin command of the zsh package. An attacker could use this flaw to cause a denial of service by crashing the user shell.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5zshWill not fix
Red Hat Enterprise Linux 6zshWill not fix
Red Hat Enterprise Linux 8zshNot affected
Red Hat Enterprise Linux 7zshFixedRHSA-2018:307330.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1549862zsh: NULL dereference in cd in sh compatibility mode under given circumstances

2 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
nvd
больше 7 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
debian
больше 7 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, th ...

CVSS3: 8.1
github
больше 3 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

oracle-oval
около 7 лет назад

ELSA-2018-3073: zsh security and bug fix update (MODERATE)

2 Low

CVSS3