Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-45444

Опубликовано: 14 фев. 2022
Источник: ubuntu
Приоритет: low
CVSS2: 5.1
CVSS3: 7.8

Описание

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

РелизСтатусПримечание
bionic

released

5.4.2-3ubuntu3.2
devel

not-affected

5.8.1-1
esm-infra/bionic

not-affected

5.4.2-3ubuntu3.2
esm-infra/focal

not-affected

5.8-3ubuntu1.1
esm-infra/xenial

released

5.1.1-1ubuntu2.3+esm1
focal

released

5.8-3ubuntu1.1
impish

released

5.8-6ubuntu0.1
jammy

needs-triage

kinetic

not-affected

5.8.1-1
lunar

not-affected

5.8.1-1

Показывать по

5.1 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 3 лет назад

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

CVSS3: 7.8
nvd
больше 3 лет назад

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

CVSS3: 7.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 3 лет назад

In zsh before 5.8.1, an attacker can achieve code execution if they co ...

rocky
около 3 лет назад

Moderate: zsh security update

5.1 Medium

CVSS2

7.8 High

CVSS3