Lucene search

K
osvGoogleOSV:RLSA-2020:0903
HistoryMar 19, 2020 - 10:45 a.m.

Important: zsh security update

2020-03-1910:45:02
Google
osv.dev
4

0.0005 Low

EPSS

Percentile

17.2%

The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell (the Korn shell), but includes many enhancements. Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions (with autoloading), a history mechanism, and more.

Security Fix(es):

  • zsh: insecure dropping of privileges when unsetting PRIVILEGED option (CVE-2019-20044)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.