security advisorysecurity issuedebian
It was discovered that zsh, a powerful shell and scripting language, did not prevent recursive prompt expansion. This would allow an attacker to execute arbitrary commands into a user's shell, for instance by tricking a vcs_info user into checking out a git branch . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5078-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 16, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zsh CVE ID : CVE-2021-45444 It was discovered that zsh, a powerful shell and scripting language, did not prevent recursive prompt expansion. This would allow an attacker to execute arbitrary commands into a user's shell, for instance by tricking a vcs_info user into checking out a git branch with a specially crafted name. For the oldstable distribution (buster), this problem has been fixed in version 5.7.1-1+deb10u1. For the stable distribution (bullseye), this problem has been fixed in version 5.8-6+deb11u1. We recommend that you upgrade your zsh packages. For the detailed security status of zsh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zsh Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Announcement DSA-5079-1 pertains to a vulnerability in curl that enables potential code execution via crafted input.. Debian Security, Zsh Update, Command Execution, Shell Vulnerability, Recursive Expansion. . Severity: Important. LinuxSecurity.com Team
Feb 16, 2022
•Important
Debian