CVE-2018-0502: Input Validation
Published Sep 5, 2018
·Updated
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.
Affected Software
5 affected componentsFixes available
debian/zsh
5.8-6+deb11u15.9-45.9-8
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Zsh zsh<5.6
Remediation
Patch Available
Event History
Sep 5, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:43 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·03:02 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-0502?
The severity of CVE-2018-0502 is critical, with a CVSS score of 9.8.
2
How does CVE-2018-0502 affect zsh?
CVE-2018-0502 affects zsh versions before 5.6.
3
Can CVE-2018-0502 lead to arbitrary code execution?
Yes, CVE-2018-0502 can potentially lead to arbitrary code execution.
4
Which operating systems are affected by CVE-2018-0502?
CVE-2018-0502 affects Canonical Ubuntu Linux versions 14.04, 16.04, and 18.04.
5
How can I fix CVE-2018-0502?
To fix CVE-2018-0502, upgrade zsh to version 5.6 or higher.