Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18206

Опубликовано: 09 мая 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

A buffer overflow flaw was found in the zsh shell symbolic link resolver. A local, unprivileged user can create a specially crafted directory path which leads to a buffer overflow in the context of the user trying to do a symbolic link resolution in the aforementioned path. If the user affected is privileged, this leads to privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5zshWill not fix
Red Hat Enterprise Linux 8zshNot affected
Red Hat Enterprise Linux 6zshFixedRHSA-2018:193219.06.2018
Red Hat Enterprise Linux 7zshFixedRHSA-2018:307330.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120->CWE-121

EPSS

Процентиль: 77%
0.01066
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

CVSS3: 9.8
nvd
больше 7 лет назад

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

CVSS3: 9.8
debian
больше 7 лет назад

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

CVSS3: 9.8
github
больше 3 лет назад

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

oracle-oval
больше 7 лет назад

ELSA-2018-1932: zsh security update (MODERATE)

EPSS

Процентиль: 77%
0.01066
Низкий

7.5 High

CVSS3