Debian Security Advisory

DLA-2117-1 zsh -- LTS security update

Date Reported:
24 Feb 2020
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 951458.
In Mitre's CVE dictionary: CVE-2019-20044.
More information:

A privilege escalation vulnerability was discovered in zsh, a shell with lots of features, whereby a user could regain a formerly elevated privelege level even when such an action should not be permitted.

For Debian 8 Jessie, this problem has been fixed in version 5.0.7-5+deb8u1.

We recommend that you upgrade your zsh packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: