CVE-2014-10070
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.
zsh, en versiones anteriores a la 5.0.7, permite la evaluación de los valores- iniciales de las variables de enteros importadas del entorno (en lugar de tratarlas como números literales). Esto podría permitir el escalado de privilegios local, bajo ciertas condiciones específicas y atípicas, cuando zsh se está invocando en contextos de elevación de privilegios en los que el entorno no se ha saneado correctamente, como cuando zsh se invoca en sistemas en los que se ha deshabilitado "env_reset".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-27 CVE Reserved
- 2018-02-27 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://zsh.sourceforge.net/releases.html | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://sourceforge.net/p/zsh/code/ci/546203a770cec329e73781c3c8ab1078390aee72 | 2018-03-21 |
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3593-1 | 2018-03-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zsh Project Search vendor "Zsh Project" | Zsh Search vendor "Zsh Project" for product "Zsh" | <= 5.0.6 Search vendor "Zsh Project" for product "Zsh" and version " <= 5.0.6" | - |
Affected
|