PT-2017-4092 · Gnu+3 · Zsh+3

Anthony Sottile

+1

·

Published

2017-11-27

·

Updated

2025-08-23

·

CVE-2018-0502

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zsh versions prior to 5.6
Description The issue is related to the incorrect handling of a script containing #!. This could potentially allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.
Recommendations For versions prior to 5.6, update to version 5.6 or later to resolve the issue. As a temporary workaround, consider restricting the execution of scripts containing #! to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2654
BDU:2021-01451
CVE-2018-0502
DLA-2470-1
OPENSUSE-SU-2018_2741-1
OPENSUSE-SU-2018_2966-1
OPENSUSE-SU-2024:11543-1
SUSE-SU-2018:2686-1
SUSE-SU-2018_2686-1
SUSE-SU-2022:0161-1
SUSE-SU-2022:14910-1
SUSE-SU-2022_0161-1
SUSE-SU-2022_14910-1
USN-3764-1

Affected Products

Alt Linux
Suse
Ubuntu
Zsh