First published: Tue Feb 27 2018(Updated: )
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zsh Zsh | <5.3 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
debian/zsh | 5.8-6+deb11u1 5.9-4 5.9-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10714 is a vulnerability in zsh before version 5.3 that allows for undersized buffers, potentially leading to a buffer overflow.
CVE-2016-10714 has a severity score of 9.8 (Critical).
Zsh versions before 5.3 are affected by CVE-2016-10714.
To fix CVE-2016-10714, make sure to update zsh to version 5.3 or higher.
You can find more information about CVE-2016-10714 in the references provided: [link1], [link2], [link3].