CVE-2014-3219
published 2018-02-09CVE-2014-3219: fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3)…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.5th percentile
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fish | < fish 2.1.1-1 (bookworm) | fish 2.1.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fishshell | fish | < 2.1.1 | 2.1.1 |
| fishshell | fish | >= 0 < 2.1.1-1 | 2.1.1-1 |
| fishshell | fish | >= 0 < 2.1.1-1 | 2.1.1-1 |
| fishshell | fish | >= 0 < 2.1.1-1 | 2.1.1-1 |
| fishshell | fish | >= 0 < 2.1.1-1 | 2.1.1-1 |
| openstack | horizon | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-django-horizon: XSS in Heat stack creation
vendor_redhat·2015-06-09·CVSS 4.3
CVE-2015-3219 [MEDIUM] CWE-79 python-django-horizon: XSS in Heat stack creation
python-django-horizon: XSS in Heat stack creation
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the help_text attribute in the Field class.
A cross-site scripting (XSS) flaw was found in the Horizon orchestration dashboard. An attacker able to trick a Horizon user into using a malicious template during the stack creation could use this flaw to perform an XSS attack on that user.
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: python-django-horizon (Red Hat Enterpri
Debian
CVE-2014-3219: fish - fish before 2.1.1 allows local users to write to arbitrary files via a symlink a...
vendor_debian·2014·CVSS 7.8
CVE-2014-3219 [HIGH] CVE-2014-3219: fish - fish before 2.1.1 allows local users to write to arbitrary files via a symlink a...
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
GHSA
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
ghsa·2022-05-17
CVE-2015-3219 [MEDIUM] CWE-79 OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the help_text attribute in the Field class.
GHSA
GHSA-x4v8-3282-qp44: fish before 2
ghsa_unreviewed·2022-05-13
CVE-2014-3219 [HIGH] CWE-59 GHSA-x4v8-3282-qp44: fish before 2
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
OSV
CVE-2014-3219: fish before 2
osv·2018-02-09·CVSS 7.8
CVE-2014-3219 [HIGH] CVE-2014-3219: fish before 2
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132751.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00071.htmlhttp://security.gentoo.org/glsa/glsa-201412-49.xmlhttp://www.openwall.com/lists/oss-security/2014/05/06/3http://www.openwall.com/lists/oss-security/2014/09/28/8http://www.securityfocus.com/bid/67115https://bugzilla.redhat.com/show_bug.cgi?id=1092091https://github.com/fish-shell/fish-shell/commit/3225d7e169a9edb2f470c26989e7bc8e0d0355cehttps://github.com/fish-shell/fish-shell/issues/1440http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132751.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00071.htmlhttp://security.gentoo.org/glsa/glsa-201412-49.xmlhttp://www.openwall.com/lists/oss-security/2014/05/06/3http://www.openwall.com/lists/oss-security/2014/09/28/8http://www.securityfocus.com/bid/67115https://bugzilla.redhat.com/show_bug.cgi?id=1092091https://github.com/fish-shell/fish-shell/commit/3225d7e169a9edb2f470c26989e7bc8e0d0355cehttps://github.com/fish-shell/fish-shell/issues/1440
2018-02-09
Published