package/zsh: security bump to version 5.8
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Fri, 28 Feb 2020 22:45:08 +0000 (23:45 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 29 Feb 2020 07:36:11 +0000 (08:36 +0100)
commit141ec698123d0c9c9b793d39d947060f001aab55
treea18db56137bf9398b8b438de3ec1045f1e7a8cc2
parent8619025300899f7d5cfcd658352c2f70794201d7
package/zsh: security bump to version 5.8

- Fix CVE-2019-20044: In Zsh before 5.8, attackers able to execute
  commands can regain privileges dropped by the --no-PRIVILEGED option.
  Zsh fails to overwrite the saved uid, so the original privileges can
  be restored by executing MODULE_PATH=/dir/with/module zmodload with a
  module that calls setuid().
- Update indentation of hash file (two spaces)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/zsh/zsh.hash
package/zsh/zsh.mk