Lucene search

K
cvelistRedhatCVELIST:CVE-2018-1100
HistoryApr 11, 2018 - 7:00 p.m.

CVE-2018-1100

2018-04-1119:00:00
CWE-120
redhat
www.cve.org

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.

CNA Affected

[
  {
    "product": "zsh",
    "vendor": "zsh",
    "versions": [
      {
        "status": "affected",
        "version": "through 5.4.2"
      }
    ]
  }
]