ZeroHour

CVE-2018-1100

CVSS 3.1
7.8 high
EPSS
<1%p43
Published
()
Modified
Description

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.

Vendors
zshcanonicalredhat
Products
zsh, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-120, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.