CVE-2018-7548

Name
CVE-2018-7548
Description
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://sourceforge.net/p/zsh/code/ci/110b13e1090bc31ac1352b28adc2d02b6d25a102
Third Party Advisory https://usn.ubuntu.com/3593-1/
Third Party Advisory https://security.gentoo.org/glsa/201805-10

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zsh:zsh:*:*:*:*:*:*:*:* zsh >= None <= 5.4.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status