CVE-2018-7548: Null Pointer Dereference
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/zshto a version that resolves this vulnerability.Fixed in 5.8-6+deb11u1Fixed in 5.9-4Fixed in 5.9-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.4.2
Event History
Frequently Asked Questions
What is CVE-2018-7548?
CVE-2018-7548 is a vulnerability in zsh through 5.4.2 that allows for a null pointer dereference when using ${(PA)...} on an empty array result.
What is the severity of CVE-2018-7548?
CVE-2018-7548 has a severity level of 9.8 (critical).
How does CVE-2018-7548 affect zsh?
CVE-2018-7548 affects zsh versions through 5.4.2.
How can I fix CVE-2018-7548 in zsh?
To fix CVE-2018-7548 in zsh, update to version 5.7.1-1+deb10u1, 5.8-6+deb11u1, 5.9-4, or 5.9-5.
Where can I find more information about CVE-2018-7548?
More information about CVE-2018-7548 can be found at the following references: [1] [2] [3].