Fedora Account System
Red Hat Associate
Red Hat Customer
A stack-based buffer overflow was found in the zsh command interpreter. An attacker could use this flaw to cause a denial of service (zsh crash), when providing a specially-crafted string as input to the zsh shell. References: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521108 https://bugs.launchpad.net/ubuntu/+source/zsh/+bug/333722 PoC: Provide following string to zsh in interactive mode: % AAAAAAAAAAAAAAAAAAAAAAAA!AAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA Please note the '!' character in the above string. Also provide the above string to /bin/zsh without newlines (they have been added only for better readability).
This issue affects all versions of the zsh package, as shipped with Red Hat Enteprise Linux 2.1, 3, 4, and 5. This issue affects all versions of the zsh package, as shipped with Fedora releases of 9, 10, and devel.
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/