CVE-2021-45444
14.02.2022, 12:15
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.Enginsight
Vendor | Product | Version |
---|---|---|
zsh | zsh | 𝑥 < 5.8.1 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
apple | mac_os_x | 10.15 ≤ 𝑥 < 10.15.7 |
apple | mac_os_x | 10.15.7:security_update_2020 |
apple | mac_os_x | 10.15.7:security_update_2020-001 |
apple | mac_os_x | 10.15.7:security_update_2020-005 |
apple | mac_os_x | 10.15.7:security_update_2020-007 |
apple | mac_os_x | 10.15.7:security_update_2021-001 |
apple | mac_os_x | 10.15.7:security_update_2021-002 |
apple | mac_os_x | 10.15.7:security_update_2021-003 |
apple | mac_os_x | 10.15.7:security_update_2021-006 |
apple | mac_os_x | 10.15.7:security_update_2021-007 |
apple | mac_os_x | 10.15.7:security_update_2021-008 |
apple | mac_os_x | 10.15.7:security_update_2022-001 |
apple | mac_os_x | 10.15.7:security_update_2022-002 |
apple | mac_os_x | 10.15.7:security_update_2022-003 |
apple | macos | 11.0 ≤ 𝑥 < 11.6.6 |
apple | macos | 12.0.0 ≤ 𝑥 < 12.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References