Hi, these two issues have been already fixed with the 5.6-1 upload which happened just minutes after the embargo for these issues was over. Because of the embargo there wasn't a proper bug report yet. So this bug report is primarily to track the fix of these issues in Debian Buster, Stretch and maybe also in Debian (E)LTS releases. From the upstream 5.6 release notes: Links into the Debian Security Tracker: https://security-tracker.debian.org/tracker/CVE-2018-0502 https://security-tracker.debian.org/tracker/CVE-2018-13259 (JFTR: The Debian Security Team doesn't consider a DSA necessary for these issues and recommends to fix the issues in Stretch via the next Debian Minor Stable Update.) Upstream release announcement: https://www.zsh.org/mla/zsh-announce/136 Upstream fix/patch: https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d (Details about affected versions will follow soon.)
* Axel Beckert [Wed Sep 05, 2018 at 02:23:05AM +0200]: [...] AFAICT this has been fixed and is no longer relevant for any supported Debian/release, so closing this issue now. regards -mika-