Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7549

Опубликовано: 22 дек. 2017
Источник: redhat
CVSS3: 3.3

Описание

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

A NULL pointer dereference flaw was found in the code responsible for saving hashtables of the zsh package. An attacker could use this flaw to cause a denial of service by crashing the user shell.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5zshNot affected
Red Hat Enterprise Linux 6zshWill not fix
Red Hat Enterprise Linux 8zshNot affected
Red Hat Enterprise Linux 7zshFixedRHSA-2018:307330.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1549858zsh: crash on copying empty hash table

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

CVSS3: 7.5
nvd
больше 7 лет назад

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

CVSS3: 7.5
debian
больше 7 лет назад

In params.c in zsh through 5.4.2, there is a crash during a copy of an ...

CVSS3: 7.5
github
больше 3 лет назад

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

oracle-oval
около 7 лет назад

ELSA-2018-3073: zsh security and bug fix update (MODERATE)

3.3 Low

CVSS3