[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Zsh Shell - (bulletinoct2018)

ID: oval:org.secpod.oval:def:2103387Date: (C)2020-01-19   (M)2023-02-20
Class: PATCHFamily: unix




zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

Platform:
Sun Solaris 11
Product:
shell/zsh
Reference:
bulletinoct2018
CVE-2014-10070
CVE-2014-10071
CVE-2014-10072
CVE-2016-10714
CVE-2017-18205
CVE-2017-18206
CVE-2018-1071
CVE-2018-1083
CVE-2018-1100
CVE-2018-7548
CVE-2018-7549
CVE    11
CVE-2016-10714
CVE-2014-10071
CVE-2014-10072
CVE-2014-10070
...
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies