ALAS2-2018-1089 --- zshID: oval:org.secpod.oval:def:1700084 | Date: (C)2018-10-16 (M)2023-12-20 |
Class: PATCH | Family: unix |
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.It was discovered that zsh does not properly validate the shebang of input files and it truncates it to the first 64 bytes. A local attacker may use this flaw to make zsh execute a different binary than what is expected, named with a substring of the shebang one.