========================================================================== Ubuntu Security Notice USN-3608-1 March 27, 2018 zsh vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Zsh. Software Description: - zsh: shell with lots of features Details: Richard Maciel Costa discovered that Zsh incorrectly handled certain inputs. An attacker could possibly use this to cause a denial of service. (CVE-2018-1071) It was discovered that Zsh incorrectly handled certain files. An attacker could possibly use this to execute arbitrary code. (CVE-2018-1083) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10: zsh 5.2-5ubuntu1.2 Ubuntu 16.04 LTS: zsh 5.1.1-1ubuntu2.2 Ubuntu 14.04 LTS: zsh 5.0.2-3ubuntu6.2 After a standard system update you need to restart Zsh to make all the necessary changes References: https://usn.ubuntu.com/usn/usn-3608-1 CVE-2018-1071, CVE-2018-1083 Package Information: https://launchpad.net/ubuntu/+source/zsh/5.2-5ubuntu1.2 https://launchpad.net/ubuntu/+source/zsh/5.1.1-1ubuntu2.2 https://launchpad.net/ubuntu/+source/zsh/5.0.2-3ubuntu6.2