First published: Tue Jan 28 2020(Updated: )
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fishshell Fish | >=2.0.0<2.1.1 | |
debian/fish | 3.1.2-3+deb11u1 3.6.0-3.1+deb12u1 3.7.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2914 is a vulnerability in fish-shell that allows remote attackers to execute arbitrary code through the configuration service.
CVE-2014-2914 is considered critical with a severity score of 9.8.
fish-shell versions 2.0.0 to 2.1.1 are affected by CVE-2014-2914.
To fix CVE-2014-2914, update fish-shell to version 3.0.2-2+deb10u1 or later.
More information about CVE-2014-2914 can be found at the following references: [1] [2] [3].