Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-1083
Description:Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2018.1208   1.3.6.1.4.1.25623.1.0.891335   1.3.6.1.4.1.25623.1.1.2.2018.1209  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-1083
BugTraq ID: 103572
http://www.securityfocus.com/bid/103572
https://security.gentoo.org/glsa/201805-10
https://lists.debian.org/debian-lts-announce/2018/03/msg00038.html
https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html
RedHat Security Advisories: RHSA-2018:1932
https://access.redhat.com/errata/RHSA-2018:1932
RedHat Security Advisories: RHSA-2018:3073
https://access.redhat.com/errata/RHSA-2018:3073
https://usn.ubuntu.com/3608-1/




© 1998-2025 E-Soft Inc. All rights reserved.