CVE-2014-3219: High severity fish shell vulnerability
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-3219?
CVE-2014-3219 is a vulnerability in fishshell before version 2.1.1 that allows local users to write to arbitrary files through a symlink attack.
How severe is CVE-2014-3219?
CVE-2014-3219 has a severity rating of 7.8 (high).
What software is affected by CVE-2014-3219?
Fishshell versions before 2.1.1, Debian 3.0.2-2+deb10u1, Debian 3.1.2-3+deb11u1, Debian 3.6.0-3.1, Debian 3.6.1-1, Fishshell 2.1.1, Fedora 19.
How can local users exploit CVE-2014-3219?
Local users can exploit CVE-2014-3219 by creating symlinks to arbitrary files, allowing them to write to those files.
Where can I find more information about CVE-2014-3219?
You can find more information about CVE-2014-3219 at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2014-3219 [2] http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132751.html [3] http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.html