fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-05-02 07:55
Updated : 2019-09-24 08:15
NVD link : CVE-2014-2905
Mitre link : CVE-2014-2905
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
fishshell
- fish