#908000 zsh: CVE-2018-0502 + CVE-2018-13259: Two security bugs in shebang line parsing

Package:
zsh
Source:
zsh
Description:
shell with lots of features
Submitter:
Axel Beckert
Date:
2026-07-17 18:45:01 UTC
Severity:
important
Tags:
#908000#5
Date:
2018-09-05 00:23:05 UTC
From:
To:
Hi,

these two issues have been already fixed with the 5.6-1 upload which
happened just minutes after the embargo for these issues was over.

Because of the embargo there wasn't a proper bug report yet. So this bug
report is primarily to track the fix of these issues in Debian Buster,
Stretch and maybe also in Debian (E)LTS releases.

From the upstream 5.6 release notes:

Links into the Debian Security Tracker:

https://security-tracker.debian.org/tracker/CVE-2018-0502
https://security-tracker.debian.org/tracker/CVE-2018-13259

(JFTR: The Debian Security Team doesn't consider a DSA necessary for
these issues and recommends to fix the issues in Stretch via the next
Debian Minor Stable Update.)

Upstream release announcement:

https://www.zsh.org/mla/zsh-announce/136

Upstream fix/patch:

https://sourceforge.net/p/zsh/code/ci/1c4c7b6a4d17294df028322b70c53803a402233d

(Details about affected versions will follow soon.)

#908000#16
Date:
2026-07-17 18:43:07 UTC
From:
To:
* Axel Beckert [Wed Sep 05, 2018 at 02:23:05AM +0200]:

[...]

AFAICT this has been fixed and is no longer relevant for any
supported Debian/release, so closing this issue now.

regards
-mika-