Red Hat Bugzilla – Bug 1626184
CVE-2018-13259 zsh: Improper handling of shebang line longer than 64
Last modified: 2018-09-17 11:24:37 EDT
An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. Upstream patch: https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d References: https://www.zsh.org/mla/zsh-announce/136
Created zsh tracking bugs for this issue: Affects: fedora-all [bug 1626185]
External References: http://www.zsh.org/mla/zsh-announce/136
Statement: This issue did not affect the versions of zsh as shipped with Red Hat Enterprise Linux 5 as scripts were directly handled by the kernel and not special-handled by zsh itself.