Back to search
CVE-2021-45444
Published: Feb 13, 2022
Modified: Aug 4, 2024
PUBLISHED
Description
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://zsh.sourceforge.io/releases.html
x_refsource_MISC
https://vuln.ryotak.me/advisories/63
x_refsource_MISC
FEDORA-2022-adf0c6d196
vendor-advisory
x_refsource_FEDORA
DSA-5078
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20220218 [SECURITY] [DLA 2926-1] zsh security update
mailing-list
x_refsource_MLIST
FEDORA-2022-0a06987c3c
vendor-advisory
x_refsource_FEDORA
https://support.apple.com/kb/HT213257
x_refsource_CONFIRM
https://support.apple.com/kb/HT213256
x_refsource_CONFIRM
https://support.apple.com/kb/HT213255
x_refsource_CONFIRM
20220516 APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina
mailing-list
x_refsource_FULLDISC
20220516 APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6
mailing-list
x_refsource_FULLDISC
20220516 APPLE-SA-2022-05-16-2 macOS Monterey 12.4
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now