Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-20044
HistoryFeb 24, 2020 - 2:15 p.m.

Command injection

2020-02-2414:15:00
PRIOn knowledge base
www.prio-n.com
12

7.7 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

References