CVE-2018-1083
Summary
| CVE | CVE-2018-1083 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-28 13:29:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2470-1] zsh security update |
MLIST |
lists.debian.org |
|
| 1557382 – (CVE-2018-1083) CVE-2018-1083 zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Zsh: Multiple vulnerabilities (GLSA 201805-10) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| zsh / Code / Commit [259ac4] |
CONFIRM |
sourceforge.net |
Patch, Third Party Advisory |
| [SECURITY] [DLA 1335-1] zsh security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| USN-3608-1: Zsh vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500832 Alpine Linux Security Update for zsh
- 504569 Alpine Linux Security Update for zsh
- 710220 Gentoo Linux Zsh Multiple Vulnerabilities (GLSA 201805-10)
- 753235 SUSE Enterprise Linux Security Update for zsh (SUSE-SU-2022:14910-1)