Back to search
CVE-2014-3219
Published: Feb 9, 2018
Modified: Aug 6, 2024
PUBLISHED
Description
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
GLSA-201412-49
vendor-advisory
x_refsource_GENTOO
FEDORA-2014-5783
vendor-advisory
x_refsource_FEDORA
[oss-security] 20140928 Security release of fish shell 2.1.1
mailing-list
x_refsource_MLIST
[oss-security] 20140506 Re: Upcoming security release of fish 2.1.1
mailing-list
x_refsource_MLIST
https://github.com/fish-shell/fish-shell/issues/1440
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1092091
x_refsource_CONFIRM
67115
vdb-entry
x_refsource_BID
openSUSE-SU-2019:2177
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2188
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now