Lucene search

K
redhatcveRedhat.comRH:CVE-2018-13259
HistorySep 06, 2018 - 5:49 p.m.

CVE-2018-13259

2018-09-0617:49:30
redhat.com
access.redhat.com
10

EPSS

0.007

Percentile

80.4%

It was discovered that zsh does not properly validate the shebang of input files and it truncates it to the first 64 bytes. A local attacker may use this flaw to make zsh execute a different binary than what is expected, named with a substring of the shebang one.