zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fellipeh/redhat_sec
- https://github.com/fhbash/redhat_sec