First published: Tue Jan 28 2020(Updated: )
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fishshell Fish | >=1.23.0<2.1.1 | |
debian/fish | 3.1.2-3+deb11u1 3.6.0-3.1+deb12u1 3.7.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3856 is high with a severity value of 7.
CVE-2014-3856 affects fish (aka fish-shell) versions 1.23.0 before 2.1.1.
Local users can gain privileges by exploiting CVE-2014-3856 through a temporary file with a predictable name.
Versions 1.23.0 before 2.1.1 of fish (aka fish-shell) are affected by CVE-2014-3856.
To fix CVE-2014-3856, it is recommended to update fish (aka fish-shell) to version 2.1.1 or higher.