{"id":"CLSA-2022-1648138003","summary":"Fix CVE(s): CVE-2019-20044, CVE-2021-45444","details":"\n   * SECURITY UPDATE: Regain dropped privileges\n     - debian/patches/CVE-2019-20044-pre.patch: change the order of the calls to\n       setgid (this should go first) and setuid in Src/options.c.\n     - debian/patches/CVE-2019-20044-1.patch: add extra checks to drop privileges\n       securely in Src/options.c.\n     - debian/patches/CVE-2019-20044-2.patch: add Src/openssh_bsd_setres_id.c\n       and its object file to Src/zsh.mdd, fix some of the checks from the\n       previous patch in Src/options.c, update compatibility wrappers in\n       Src/zsh_system.h, update the uid/gid methods in AC_CHECK_FUNCS in\n       configure.ac and add a test in Test/E01options.ztst.\n     - debian/patches/CVE-2019-20044-3.patch: improve Src/options.c changes from\n       above two patches.\n     - debian/patches/CVE-2019-20044-4.patch: clean up white spaces in\n       Src/options.c.\n     - debian/patches/CVE-2019-20044-5.patch: add privileged tests to\n       Test/P01privileged.ztst, remove the notes on privileged test in\n       Test/E01options.ztst and add the prilived tests to the Test/README.\n     - CVE-2019-20044\n   * SECURITY UPDATE: Arbitrary code execution\n     - debian/patches/CVE-2021-45444.patch: save PROMPTSUBST option before\n       the call to promptexpand() in b/Src/prompt.c and restore after it is\n       executed.\n     - CVE-2021-45444","modified":"2026-06-04T09:45:40.322210210Z","published":"2022-03-24T16:06:43Z","upstream":["CVE-2019-20044","CVE-2021-45444"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2022-1648138003"}],"affected":[{"package":{"name":"zsh","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/zsh?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-1ubuntu2.3+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1648138003.json"}},{"package":{"name":"zsh-common","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/zsh-common?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-1ubuntu2.3+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1648138003.json"}},{"package":{"name":"zsh-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/zsh-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-1ubuntu2.3+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1648138003.json"}},{"package":{"name":"zsh-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/zsh-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-1ubuntu2.3+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1648138003.json"}},{"package":{"name":"zsh-static","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/zsh-static?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-1ubuntu2.3+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1648138003.json"}}],"schema_version":"1.7.5"}