CVE-2014-10071: Buffer Overflow
A flaw was found in zsh prior 5.0.7. There is a buffer overflow for very long fds in >& fd syntax.
References: https://sourceforge.net/p/zsh/code/ci/49a3086bb67575435251c70ee598e2fd406ef055
Other sources
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2014-10071.
What is the severity of CVE-2014-10071?
The severity of CVE-2014-10071 is critical with a severity value of 9.8.
What software is affected by CVE-2014-10071?
The software affected by CVE-2014-10071 includes zsh versions before 5.0.7.
How can I fix CVE-2014-10071?
To fix CVE-2014-10071, update zsh to version 5.0.7 or later.
Where can I find more information about CVE-2014-10071?
You can find more information about CVE-2014-10071 at the following references: [Reference 1](https://sourceforge.net/p/zsh/code/ci/49a3086bb67575435251c70ee598e2fd406ef055), [Reference 2](https://usn.ubuntu.com/3593-1/), [Reference 3](https://access.redhat.com/errata/RHSA-2018:3073).