Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Gentoo: GLSA-201903-02 Normal: Zsh Arbitrary Code Execution Risk

gentoo
Calendar Grey March 10, 2019
Dist Gentoo Esm H88
Vulnerabilities in Zsh's input handling expose systems to potential code execution threats. To mitigate risks, ensure you are running the most recent version.
Input validation errors in Zsh could result in arbitrary code execution.

Summary

Two input validation errors have been discovered in how Zsh parses scripts: * Parsing a malformed shebang line could cause Zsh to call a program listed in the second line (CVE-2018-0502) * Shebang lines longer than 64 characters are truncated (CVE-2018-13259)

Resolution

All Zsh users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-shells/zsh-5.6"

References

[ 1 ] CVE-2018-0502 https://nvd.nist.gov/vuln/detail/CVE-2018-0502 [ 2 ] CVE-2018-13259 https://nvd.nist.gov/vuln/detail/CVE-2018-13259

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201903-02
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: Normal
Title: Zsh: User-assisted execution of arbitrary code
Date: March 10, 2019
Bugs: #665278
ID: 201903-02

Synopsis

Input validation errors in Zsh could result in arbitrary code execution.

Background

A shell designed for interactive use, although it is also a powerful scripting language.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-shells/zsh < 5.6 >= 5.6

Impact

===== An attacker could entice a user to execute a specially crafted script using Zsh, possibly resulting in execution of arbitrary code with the privileges of the process.

Workaround

There is no known workaround at this time.

Your message here