CVE-2019-20044

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/02/2020
Last modified:
07/11/2023

Description

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zsh:zsh:*:*:*:*:*:*:*:* 5.8 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 13.5 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 13.5 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.15.5 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.13.0 (including) 10.13.6 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.14.0 (including) 10.14.6 (excluding)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.15 (including) 10.15.5 (excluding)
cpe:2.3:o:apple:mac_os_x:10.13.6:-:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2018-002:*:*:*:*:*:*