Back to Database
Status published
High
CVE-2018-1100
zsh through version 5.4.2 is vulnerable to a stack-based buffer...
Vulnerability Description
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1100
Credits & Attribution
No credits recorded in the NVD database.
References
- https://sourceforge.net/p/zsh/code/ci/31f72205630687c1cef89347863aab355296a27f/
- https://usn.ubuntu.com/3764-1/
- https://security.gentoo.org/glsa/201805-10
- https://access.redhat.com/errata/RHSA-2018:1932
- https://bugzilla.redhat.com/show_bug.cgi?id=1563395
- https://access.redhat.com/errata/RHSA-2018:3073
- https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html
More from zsh
View All →CVE-2021-45444
In zsh before 5.8.1, an attacker can achieve code execution...
High
7.8
CVE-2019-20044
In Zsh before 5.8, attackers able to execute commands can...
High
7.8
CVE-2018-7549
In params.c in zsh through 5.4.2, there is a crash...
High
7.5
CVE-2018-7548
In subst.c in zsh through 5.4.2, there is a NULL...
Critical
9.8
CVE-2018-1083
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow...
High
7.8
Affected Vendor
Affected Software
zsh
Vulnerable Versions:
through 5.4.2
Timeline
Official Publish:
April 11th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H