New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] zsh (SSA:2019-013-01) New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/zsh-5.6.2-i586-1_slack14.2.txz: Upgraded. This release fixes security issues, including ones that could allow a local attacker to execute arbitrary code. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-18205 https://www.cve.org/CVERecord?id=CVE-2017-18206 https://www.cve.org/CVERecord?id=CVE-2018-1071 https://www.cve.org/CVERecord?id=CVE-2018-1083 https://www.cve.org/CVERecord?id=CVE-2018-1100 https://www.cve.org/CVERecord?id=CVE-2018-7548 https://www.cve.org/CVERecord?id=CVE-2018-7549 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/zsh-5.6.2-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/zsh-5.6.2-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/zsh-5.6.2-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/zsh-5.6.2-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/zsh-5.6.2-i586-1_slack14.2.txz Updated package for Slackware x86_6414.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/zsh-5.6.2-x86_64-1_slack14.2.txz MD5 signatures: +-------------+ Slackware 14.0 package: eee31011db16ee065279399d58de4c2b zsh-5.6.2-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 766df0eb186d95362a78ae523b83f7d2 zsh-5.6.2-x86_64-1_slack14.0.txz Slackware 14.1 package: 7c376a74372346613fa58296b5a43158 zsh-5.6.2-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 80cee93fdaa1d7d526c2056b0c374ba5 zsh-5.6.2-x86_64-1_slack14.1.txz Slackware 14.2 package: 01e67f2f735ffb022890a1adb8318b6b zsh-5.6.2-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 5e5676c283d4267057eeef2a573dae00 zsh-5.6.2-x86_64-1_slack14.2.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg zsh-5.6.2-i586-1_slack14.2.txz +-----+ . Recent updates for zsh packages have been released for Slackware 14.x to address security vulnerabilities impacting local users.. Slackware Security Updates, Zsh Security Fixes, Local Code Execution. . Severity: Critical. LinuxSecurity.com Team
The package zsh before version 5.5-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201804-7 ======================================== Severity: Medium Date : 2018-04-19 CVE-ID : CVE-2018-7548 CVE-2018-7549 Package : zsh Type : denial of service Remote : No Link : https://security.archlinux.org/AVG-642 Summary ====== The package zsh before version 5.5-1 is vulnerable to denial of service. Resolution ========= Upgrade to 5.5-1. # pacman -Syu "zsh> =5.5-1" The problems have been fixed upstream in version 5.5. Workaround ========= None. Description ========== - CVE-2018-7548 (denial of service) In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. - CVE-2018-7549 (denial of service) In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. Impact ===== A local attacker can cause a denial of service via a specially input. References ========= https://security.archlinux.org/CVE-2018-7548 https://security.archlinux.org/CVE-2018-7549 . Enhance Arch Linux security by updating zsh to fix denial of service vulnerabilities per Security Advisory ASA-201804-7. Follow these steps:. Arch Linux Denial of Service,zsh Package Security,Medium Severity Advisory,Security Update Arch Linux. . Severity: Medium. LinuxSecurity.com Team
The package zsh before version 5.5-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201804-5 ======================================== Severity: High Date : 2018-04-11 CVE-ID : CVE-2018-1100 Package : zsh Type : arbitrary code execution Remote : No Link : https://security.archlinux.org/AVG-669 Summary ====== The package zsh before version 5.5-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 5.5-1. # pacman -Syu "zsh> =5.5-1" The problem has been fixed upstream in version 5.5. Workaround ========= None. Description ========== A stack-based buffer overflow has been found in zsh
Get the latest Linux and open source security news straight to your inbox.