CVE-2017-18206: Buffer Overflow
A flaw was found in zsh prior 5.3.1. There was no check when copying to the internal xbuf2 for a preliminary test.
References: https://sourceforge.net/p/zsh/code/ci/c7a9cf465dd620ef48d586026944d9bd7a0d5d6d
Other sources
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-18206.
What is the severity of CVE-2017-18206?
The severity of CVE-2017-18206 is critical (9.8).
Which software versions are affected?
The affected software versions include zsh before 5.4.
How can I fix CVE-2017-18206?
To fix CVE-2017-18206, update zsh to version 5.4 or higher.
Where can I find more information about CVE-2017-18206?
You can find more information about CVE-2017-18206 in the references provided: [Reference 1](https://access.redhat.com/errata/RHSA-2018:1932), [Reference 2](https://access.redhat.com/errata/RHSA-2018:3073), [Reference 3](https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html).