This update for zsh fixes the following issues: - CVE-2019-20044: Fixed an insecure dropping of privileges when unsetting the PRIVILEGED option (bsc#1163882). - CVE-2018-13259: Fixed an unexpected truncation of long shebang lines (bsc#1107294). - CVE-2018-7549: Fixed a crash when an empty hash table (bsc#1082991). - CVE-2018-1083: Fixed a stack-based buffer overflow when using tab completion on directories with long names (bsc#1087026). - CVE-2018-1071: Fixed a stack-based buffer overflow when executing certain commands (bsc#1084656). - CVE-2018-0502: Fixed a mishandling of shebang lines (bsc#1107296). - CVE-2017-18206: Fixed a buffer overflow related to symlink processing (bsc#1083002). - CVE-2017-18205: Fixed an application crash when using cd with no arguments (bsc#1082998).
#1082885 #1082975 #1082977 #1082991 #1082998
#1083002 #1083250 #1084656 #1087026 #1107294
#1107296 #1163882
Cross- CVE-2014-10070 CVE-2014-10071 CVE-2014-10072
CVE-2016-10714 CVE-2017-18205 CVE-2017-18206
CVE-2018-0502 CVE-2018-1071 CVE-2018-1083
CVE-2018-13259 CVE-2018-7549 CVE-2019-20044
CVSS scores:
CVE-2014-10070 (SUSE): 8.6 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2014-10071 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2014-10071 (SUSE): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVE-2014-10072 (SUSE): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVE-2016-10714 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2016-10714 (SUSE): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Get the latest Linux and open source security news straight to your inbox.