High severity7.8NVD Advisory· Published Mar 28, 2018· Updated Jun 17, 2026
CVE-2018-1083
CVE-2018-1083
Description
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords7 versionspkg:rpm/opensuse/zsh&distro=openSUSE%20Tumbleweedpkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/zsh&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3
< 5.8-7.7+ 6 more
- (no CPE)range: < 5.8-7.7
- (no CPE)range: < 5.0.5-6.7.2
- (no CPE)range: < 5.5-3.3.15
- (no CPE)range: < 4.3.6-67.9.8.1
- (no CPE)range: < 4.3.6-67.9.8.1
- (no CPE)range: < 5.0.5-6.7.2
- (no CPE)range: < 5.0.5-6.7.2
Patches
Vulnerability mechanics
References
9- sourceforge.net/p/zsh/code/ci/259ac472eac291c8c103c7a0d8a4eaf3c2942ed7nvdPatchThird Party Advisory
- www.securityfocus.com/bid/103572nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:1932nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:3073nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/03/msg00038.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201805-10nvdThird Party Advisory
- usn.ubuntu.com/3608-1/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/12/msg00000.htmlnvd
News mentions
0No linked articles in our index yet.