CVE-2018-1100: Buffer Overflow
Last updated 24 July 2024
Other sources
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-1100?
CVE-2018-1100 is a vulnerability in zsh through version 5.4.2 that allows a local attacker to execute arbitrary code in the context of another user.
How severe is CVE-2018-1100?
CVE-2018-1100 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2018-1100?
CVE-2018-1100 affects zsh versions up to and including 5.4.2.
Are there any remedies for CVE-2018-1100?
Yes, updating zsh to version 5.7.1-1+deb10u1 or later, or 5.8-6+deb11u1 or later can remedy CVE-2018-1100.
Where can I find more information about CVE-2018-1100?
More information about CVE-2018-1100 can be found in the following references: [link1](https://access.redhat.com/errata/RHSA-2018:1932), [link2](https://access.redhat.com/errata/RHSA-2018:3073), [link3](https://bugzilla.redhat.com/show_bug.cgi?id=1563395).