CVE-2014-2914: Input Validation
Published Jan 28, 2020
·Updated
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fishconfig), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by setprompt.
Affected Software
2 affected componentsFixes available
debian/fish
3.1.2-3+deb11u13.6.0-3.1+deb12u13.7.1-1
Fishshell Fish>=2.0.0<2.1.1
Event History
Jan 28, 2020
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Frequently Asked Questions
1
What is CVE-2014-2914?
CVE-2014-2914 is a vulnerability in fish-shell that allows remote attackers to execute arbitrary code through the configuration service.
2
How severe is CVE-2014-2914?
CVE-2014-2914 is considered critical with a severity score of 9.8.
3
Which versions of fish-shell are affected by CVE-2014-2914?
fish-shell versions 2.0.0 to 2.1.1 are affected by CVE-2014-2914.
4
How can I fix CVE-2014-2914?
To fix CVE-2014-2914, update fish-shell to version 3.0.2-2+deb10u1 or later.
5
Where can I find more information about CVE-2014-2914?
More information about CVE-2014-2914 can be found at the following references: [1] [2] [3].