CVE-2018-1071: Buffer Overflow
Last updated 25 August 2025
Other sources
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1071?
CVE-2018-1071 is a vulnerability in zsh through version 5.4.2 that allows for a stack-based buffer overflow.
What is the severity of CVE-2018-1071?
CVE-2018-1071 has a severity rating of 5.5 (medium).
How does CVE-2018-1071 affect zsh?
CVE-2018-1071 affects zsh through version 5.4.2.
How can a local attacker exploit CVE-2018-1071?
A local attacker can exploit CVE-2018-1071 to cause a denial of service.
Where can I find more information about CVE-2018-1071?
You can find more information about CVE-2018-1071 at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1071), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-3608-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-1071).