|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2018-9cdf18a850 (zsh)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 26 Update: zsh-5.3.1-7.fc26
Date:  Tue, 20 Mar 2018 17:37:50 +0000 (UTC)
Message-ID:  <20180320173750.B3A4760A65E8@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-9cdf18a850 2018-03-20 17:27:15.777575 -------------------------------------------------------------------------------- Name : zsh Product : Fedora 26 Version : 5.3.1 Release : 7.fc26 URL : http://zsh.sourceforge.net/ Summary : Powerful interactive shell Description : The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell (the Korn shell), but includes many enhancements. Zsh supports command line editing, built-in spelling correction, programmable command completion, shell functions (with autoloading), a history mechanism, and more. -------------------------------------------------------------------------------- Update Information: - avoid crash when copying empty hash table (CVE-2018-7549) - avoid NULL dereference when using ```${(PA)...}``` on an empty array (CVE-2018-7548) - fix buffer overrun in xsymlinks (CVE-2017-18206) - fix NULL dereference in cd (CVE-2017-18205) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1549842 - CVE-2018-7548 zsh: null-pointer deref when using ${(PA)...} on an empty array result [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1549842 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade zsh' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds