Related Vulnerabilities: CVE-2018-7548  

In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

Severity Medium

Remote No

Type Denial of service

Description

In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

AVG-642 zsh 5.4.2-2 5.5-1 Medium Fixed

19 Apr 2018 ASA-201804-7 AVG-642 zsh Medium denial of service

https://sourceforge.net/p/zsh/code/ci/110b13e1090bc31ac1352b28adc2d02b6d25a102