Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0168
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0168)
Resumen:The remote host is missing an update for the 'zsh' package(s) announced via the MGASA-2018-0168 advisory.
Descripción:Summary:
The remote host is missing an update for the 'zsh' package(s) announced via the MGASA-2018-0168 advisory.

Vulnerability Insight:
Zsh has been updated to fix 4 security issues.

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a
NULL pointer dereference during processing of the cd command with no argument if
HOME is not set. (CVE-2017-18205)

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
(CVE-2017-18206)

In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using
${(PA)...} on an empty array result.(CVE-2018-7548)

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty
hash table, as demonstrated by typeset -p. (CVE-2018-7549)

Affected Software/OS:
'zsh' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-18205
https://security.gentoo.org/glsa/201805-10
https://sourceforge.net/p/zsh/code/ci/eb783754bdb74377f3cea4ceca9c23a02ea1bf58
RedHat Security Advisories: RHSA-2018:3073
https://access.redhat.com/errata/RHSA-2018:3073
https://usn.ubuntu.com/3593-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-18206
https://sourceforge.net/p/zsh/code/ci/c7a9cf465dd620ef48d586026944d9bd7a0d5d6d
https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html
RedHat Security Advisories: RHSA-2018:1932
https://access.redhat.com/errata/RHSA-2018:1932
Common Vulnerability Exposure (CVE) ID: CVE-2018-7548
https://sourceforge.net/p/zsh/code/ci/110b13e1090bc31ac1352b28adc2d02b6d25a102
Common Vulnerability Exposure (CVE) ID: CVE-2018-7549
https://sourceforge.net/p/zsh/code/ci/c2cc8b0fbefc9868fa83537f5b6d90fc1ec438dd
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.