CVE-2017-18205

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
27/02/2018
Last modified:
31/10/2018

Description

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zsh_project:zsh:*:*:*:*:*:*:*:* 5.4 (excluding)