Total vulnerabilities in the database
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Software | From | Fixed in |
---|---|---|
zsh / zsh | - | 5.8.1 |
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |
apple / mac_os_x | 10.15 | 10.15.7 |
apple / mac_os_x | 10.15.7-security_update_2020-005 | 10.15.7-security_update_2020-005.x |
apple / mac_os_x | 10.15.7-security_update_2020-007 | 10.15.7-security_update_2020-007.x |
apple / mac_os_x | 10.15.7-security_update_2020-001 | 10.15.7-security_update_2020-001.x |
apple / mac_os_x | 10.15.7-security_update_2020 | 10.15.7-security_update_2020.x |
apple / mac_os_x | 10.15.7-security_update_2021-001 | 10.15.7-security_update_2021-001.x |
apple / mac_os_x | 10.15.7-security_update_2021-002 | 10.15.7-security_update_2021-002.x |
apple / mac_os_x | 10.15.7-security_update_2021-003 | 10.15.7-security_update_2021-003.x |
apple / mac_os_x | 10.15.7-security_update_2021-006 | 10.15.7-security_update_2021-006.x |
apple / mac_os_x | 10.15.7-security_update_2021-008 | 10.15.7-security_update_2021-008.x |
apple / mac_os_x | 10.15.7-security_update_2021-007 | 10.15.7-security_update_2021-007.x |
apple / mac_os_x | 10.15.7-security_update_2022-002 | 10.15.7-security_update_2022-002.x |
apple / mac_os_x | 10.15.7-security_update_2022-001 | 10.15.7-security_update_2022-001.x |
apple / macos | 11.0 | 11.6.6 |
apple / mac_os_x | 10.15.7-security_update_2022-003 | 10.15.7-security_update_2022-003.x |
apple / macos | 12.0.0 | 12.4 |