← Back

CVE-2014-2905

nvd nist
Published: May 2, 2014Modified: May 6, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

Affected (2)

Products: Fishshell: Fish
1 product
Fish
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fishshell
Version 1.16.0
Version 2.0.0

Related CWEs

Timeline

No history available yet.