Debian Fish vulnerabilities
7 known vulnerabilities affecting debian/fish.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1LOW5
Vulnerabilities
Page 1 of 1
CVE-2023-49284LOWCVSS 3.9fixed in fish 3.6.0-3.1+deb12u1 (bookworm)2023
CVE-2023-49284 [LOW] CVE-2023-49284: fish - fish is a smart and user-friendly command line shell for macOS, Linux, and the r...
fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe internal representation. While this may cause unexpe
debian
CVE-2022-20001HIGHCVSS 7.8fixed in fish 3.4.0+ds-1 (bookworm)2022
CVE-2022-20001 [HIGH] CVE-2022-20001: fish - fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulner...
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display info
debian
CVE-2014-2914CRITICALCVSS 9.8fixed in fish 2.1.1-1 (bookworm)2014
CVE-2014-2914 [CRITICAL] CVE-2014-2914: fish - fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configu...
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixe
debian
CVE-2014-2906LOWCVSS 7.0fixed in fish 2.1.1-1 (bookworm)2014
CVE-2014-2906 [HIGH] CVE-2014-2906: fish - The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly...
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: re
debian
CVE-2014-2905LOWCVSS 6.9fixed in fish 2.1.1-1 (bookworm)2014
CVE-2014-2905 [MEDIUM] CVE-2014-2905: fish - fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credential...
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixi
debian
CVE-2014-3219LOWCVSS 7.8fixed in fish 2.1.1-1 (bookworm)2014
CVE-2014-3219 [HIGH] CVE-2014-3219: fish - fish before 2.1.1 allows local users to write to arbitrary files via a symlink a...
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fi
debian
CVE-2014-3856LOWCVSS 7.0fixed in fish 2.1.1-1 (bookworm)2014
CVE-2014-3856 [HIGH] CVE-2014-3856: fish - The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not proper...
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (f
debian