CVE-2014-2905
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
02/05/2014
Last modified:
12/04/2025
Description
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fishshell:fish:1.16.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fishshell:fish:2.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00071.html
- http://www.openwall.com/lists/oss-security/2014/04/28/4
- https://github.com/fish-shell/fish-shell/issues/1436
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00071.html
- http://www.openwall.com/lists/oss-security/2014/04/28/4
- https://github.com/fish-shell/fish-shell/issues/1436



