漏洞信息详情
Zsh 安全漏洞
漏洞简介
Zsh是一款可用作交互式登录的shell及脚本编写的命令解释器。
Zsh 5.8之前版本中存在安全漏洞,该漏洞源于程序没有覆盖原来存储的uid。攻击者可利用该漏洞恢复原来的权限。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.zsh.org/mla/zsh-announce/141
参考网址
来源:GENTOO
链接:https://security.gentoo.org/glsa/202003-55
来源:CONFIRM
链接:https://support.apple.com/HT211168
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2020/May/53
来源:CONFIRM
链接:https://support.apple.com/HT211175
来源:MISC
链接:https://www.zsh.org/mla/zsh-announce/141
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/12/msg00000.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/03/msg00004.html
来源:CONFIRM
链接:https://support.apple.com/kb/HT211171
来源:MISC
链接:http://zsh.sourceforge.net/releases.html
来源:CONFIRM
链接:https://support.apple.com/kb/HT211170
来源:CONFIRM
链接:https://support.apple.com/kb/HT211175
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2020/May/59
来源:CONFIRM
链接:https://support.apple.com/HT211171
来源:MISC
链接:https://github.com/XMB5/zsh-privileged-upgrade
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2020/May/49
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/PN5V7MPHRRP7QNHOEK56S7QGRU53WUN6/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/FP64FFIZI2CKQOEAOI5A72PVQULE7ZZC/
来源:CONFIRM
链接:https://support.apple.com/kb/HT211168
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2020/May/55
来源:CONFIRM
链接:https://support.apple.com/HT211170
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156924/Red-Hat-Security-Advisory-2020-0978-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1861/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Zsh-privilege-escalation-via-zmodload-31713
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0769/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0988/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156805/Red-Hat-Security-Advisory-2020-0892-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4265/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0973/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-20044
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0952/
来源:support.apple.com
链接:https://support.apple.com/kb/HT211168
来源:support.apple.com
链接:https://support.apple.com/en-us/HT211170
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156818/Red-Hat-Security-Advisory-2020-0903-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1081/
来源:support.apple.com
链接:https://support.apple.com/kb/HT211170
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157883/Apple-Security-Advisory-2020-05-26-4.html
受影响实体
暂无
补丁
- Zsh 安全漏洞的修复措施<!--2020-2-24-->
还没有评论,来说两句吧...