CVE-2014-2905

high

Description

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

References

https://github.com/fish-shell/fish-shell/issues/1436

http://www.openwall.com/lists/oss-security/2014/04/28/4

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00071.html

http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.html

Details

Source: Mitre, NVD

Published: 2014-05-02

Updated: 2019-09-24

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High