Bugzilla – Bug 1082885
VUL-0: CVE-2014-10070: zsh: privilege escalation via environment variables
Last modified: 2022-03-14 20:19:38 UTC
fixed in zsh 5.0.7: Contains a security fix to disallow evaluation of the initial values of integer variables imported from the environment (they are instead treated as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.
Fix: https://sourceforge.net/p/zsh/code/ci/546203a770cec329e73781c3c8ab1078390aee72 Test: https://sourceforge.net/p/zsh/code/ci/fb707c0acbea8b3e06eb6ff9781481929c67d926
Test: env SHLVL=1+RANDOM zsh -f -c 'print $SHLVL' 13957 Expected output: 2 Affected codestreams: SUSE:SLE-11:Update SUSE:SLE-12:Update
Also affected: SUSE:SLE-10-SP3:Update
SUSE-SU-2018:1072-1: An update that solves 9 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1082885,1082975,1082977,1082991,1082998,1083002,1083250,1084656,1087026,896914 CVE References: CVE-2014-10070,CVE-2014-10071,CVE-2014-10072,CVE-2016-10714,CVE-2017-18205,CVE-2017-18206,CVE-2018-1071,CVE-2018-1083,CVE-2018-7549 Sources used: SUSE Linux Enterprise Server 12-SP3 (src): zsh-5.0.5-6.7.2 SUSE Linux Enterprise Desktop 12-SP3 (src): zsh-5.0.5-6.7.2
openSUSE-SU-2018:1093-1: An update that solves 9 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1082885,1082975,1082977,1082991,1082998,1083002,1083250,1084656,1087026,896914 CVE References: CVE-2014-10070,CVE-2014-10071,CVE-2014-10072,CVE-2016-10714,CVE-2017-18205,CVE-2017-18206,CVE-2018-1071,CVE-2018-1083,CVE-2018-7549 Sources used: openSUSE Leap 42.3 (src): zsh-5.0.5-9.3.1
SUSE-SU-2022:14910-1: An update that fixes 12 vulnerabilities is now available. Category: security (important) Bug References: 1082885,1082975,1082977,1082991,1082998,1083002,1083250,1084656,1087026,1107294,1107296,1163882 CVE References: CVE-2014-10070,CVE-2014-10071,CVE-2014-10072,CVE-2016-10714,CVE-2017-18205,CVE-2017-18206,CVE-2018-0502,CVE-2018-1071,CVE-2018-1083,CVE-2018-13259,CVE-2018-7549,CVE-2019-20044 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): zsh-4.3.6-67.9.8.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): zsh-4.3.6-67.9.8.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): zsh-4.3.6-67.9.8.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): zsh-4.3.6-67.9.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.