Logo
vulnerabilityCVE-2021-45444
Name
CVE-2021-45444
Source
NVD ( link)Debian ( link)
Description
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
zsh
Patched

Vulnerability Ratings#


7.8
CVSSv31
5.1
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.9
Not Affected
buildroot
master
5.9
Not Affected
openwrt
master
5.9.1-r1
Not Affected
openwrt
openwrt-25.12
5.9-r4
Not Affected
yocto
master
5.9.1
Not Affected
yocto
scarthgap
5.8
Patched

Resolved with patches#


zsh (yocto:kirkstone)

#
Title
Author
Resolve
1
security/41: Don't perform PROMPT_SUBST evaluation on
Oliver Kiddle <opk@zsh.org>
CVE-2021-45444
2
security/89: Add patch which can optionally be used to
Marc Cornellà <hello@mcornella.com>
CVE-2021-45444
3
CVE-2021-45444: Update NEWS/README
dana <dana@dana.is>
CVE-2021-45444

zsh (yocto:scarthgap)

#
Title
Author
Resolve
1
security/41: Don't perform PROMPT_SUBST evaluation on
Oliver Kiddle <opk@zsh.org>
CVE-2021-45444
2
security/89: Add patch which can optionally be used to
Marc Cornellà <hello@mcornella.com>
CVE-2021-45444
3
CVE-2021-45444: Update NEWS/README
dana <dana@dana.is>
CVE-2021-45444