| Summary: | zsh new security issue CVE-2019-20044 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, geiger.david68210, herman.viaene, shlomif, sysadmin-bugs, tmb |
| Version: | 7 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7-64-OK | ||
| Source RPM: | zsh-5.7.1-2.mga8.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2020-02-24 23:35:03 CET
David Walser
2020-02-24 23:35:15 CET
Status comment:
(none) =>
Fixed upstream in 5.8 Various committers, so assigning globally; CC Shlomi as the registered maintainer. Assignee:
bugsquad =>
pkg-bugs Done for both Cauldron and mga7! CC:
(none) =>
geiger.david68210 Advisory: ======================== Updated zsh packages fix security vulnerability: A privilege escalation vulnerability was discovered in zsh, whereby a user could regain a formerly elevated privelege level even when such an action should not be permitted (CVE-2019-20044). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20044 https://www.debian.org/lts/security/2020/dla-2117 ======================== Updated packages in core/updates_testing: ======================== zsh-5.7.1-1.1.mga7 zsh-doc-5.7.1-1.1.mga7 from zsh-5.7.1-1.1.mga7.src.rpm Assignee:
pkg-bugs =>
qa-bugs MGA7-64 Plasma on Lenovo B50 No installation issues ref bug 22846 for testing: changed the user's shell to zsh, logged off and on again. Run konsole and fill out the options for history and completion. $ more .zshrc # Lines configured by zsh-newuser-install HISTFILE=~/.histfile HISTSIZE=1000 SAVEHIST=1000 # End of lines configured by zsh-newuser-install # The following lines were added by compinstall zstyle :compinstall filename '/home/tester7/.zshrc' autoload -Uz compinit compinit # End of lines added by compinstall $ echo $SHELL /bin/zsh Run a series of ls and cd commands using history an completion, all OK CC:
(none) =>
herman.viaene Validating. Advisory in Comment 3. CC:
(none) =>
andrewsfarm, sysadmin-bugs
Thomas Backlund
2020-02-29 13:51:00 CET
CC:
(none) =>
tmb An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2020-0107.html Status:
NEW =>
RESOLVED |