In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "zsh", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-beta", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-beta-doc", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-common", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-dbg", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-dbgsym", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-dev", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-doc", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-static", "binary_version": "5.0.2-3ubuntu6.1" }, { "binary_name": "zsh-static-dbgsym", "binary_version": "5.0.2-3ubuntu6.1" } ] }