First published: Tue Feb 27 2018(Updated: )
A flaw was found in zsh prior 5.4.2. There is a crash when copying empty hash table with typeset -p. Resources: <a href="https://sourceforge.net/p/zsh/code/ci/c2cc8b0fbefc9868fa83537f5b6d90fc1ec438dd">https://sourceforge.net/p/zsh/code/ci/c2cc8b0fbefc9868fa83537f5b6d90fc1ec438dd</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zsh Zsh | <=5.4.2 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
redhat/zsh | <5.5 | 5.5 |
debian/zsh | 5.8-6+deb11u1 5.9-4 5.9-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7549 is a vulnerability in zsh through version 5.4.2 that can cause a crash during a copy of an empty hash table.
CVE-2018-7549 has a severity rating of 7.5 (High).
The vulnerability affects zsh versions up to and including 5.4.2.
To fix CVE-2018-7549, update zsh to version 5.5 or above.
More information about CVE-2018-7549 can be found at the following references: [CVE-2018-7549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7549), [USN-3593-1](https://ubuntu.com/security/notices/USN-3593-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-7549).