zsh: Improper handling of shebang line longer than 64
Published Sep 5, 2018
9.8
CRITICALCVSS 3.0
EPSS 2.72%
Description
An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one.
Affected products
- Vendor n/a Product Zsh Before 5.6 Defaultn/a
- Version zsh before 5.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Zsh Before 5.6 | n/a |
|
Configuration 1
- 14.04
- 16.04
- 18.04
No data.
Red Hat Enterprise Linux 7
zsh-0:5.0.2-33.el7
Fixed · RHSA-2019:2017
Red Hat Enterprise Linux 5
zsh
Not affected
Red Hat Enterprise Linux 6
zsh
Will not fix
Red Hat Enterprise Linux 8
zsh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | zsh-0:5.0.2-33.el7 | Fixed | RHSA-2019:2017 |
| Red Hat Enterprise Linux 5 | zsh | Not affected | n/a |
| Red Hat Enterprise Linux 6 | zsh | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | zsh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of zsh as shipped with Red Hat Enterprise Linux 5 as scripts were directly handled by the kernel and not special-handled by zsh itself.
References (12)
- http://www.zsh.org/mla/zsh-announce/136
- https://access.redhat.com/errata/RHSA-2019:2017 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-13259 Vendor Advisory
- https://bugs.debian.org/908000 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1626184 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-13259
- https://security.gentoo.org/glsa/201903-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d x_refsource_MISCPatchThird Party Advisory
- https://usn.ubuntu.com/3764-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-13259
- https://www.zsh.org/mla/zsh-announce/136 x_refsource_MISCMailing ListRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.zsh.org/mla/zsh-announce/136 | ||
| https://access.redhat.com/errata/RHSA-2019:2017 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-13259 | Vendor Advisory | |
| https://bugs.debian.org/908000 | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1626184 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-13259 | ||
| https://security.gentoo.org/glsa/201903-02 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d | x_refsource_MISCPatchThird Party Advisory | |
| https://usn.ubuntu.com/3764-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-13259 | ||
| https://www.zsh.org/mla/zsh-announce/136 | x_refsource_MISCMailing ListRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.