An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. Upstream patch: https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d References: https://www.zsh.org/mla/zsh-announce/136
Created zsh tracking bugs for this issue: Affects: fedora-all [bug 1626185]
External References: http://www.zsh.org/mla/zsh-announce/136
Statement: This issue did not affect the versions of zsh as shipped with Red Hat Enterprise Linux 5 as scripts were directly handled by the kernel and not special-handled by zsh itself.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2017 https://access.redhat.com/errata/RHSA-2019:2017
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-13259