6.9
CVSSv2

CVE-2014-2905

Published: 02/05/2014 Updated: 24/09/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

fish (aka fish-shell) 1.16.0 prior to 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fishshell fish 1.16.0

fishshell fish 2.0.0

Vendor Advisories

Debian Bug report logs - #746259 fish: CVE-2014-2905 CVE-2014-2906 CVE-2014-2914 CVE-2014-3219 CVE-2014-3856 Package: src:fish; Maintainer for src:fish is Tristan Seligmann <mithrandi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 28 Apr 2014 15:09:01 UTC Severity: grave Tags: security, ...