CVE-2014-2914
28.01.2020, 16:15
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.Enginsight
Vendor | Product | Version |
---|---|---|
fishshell | fish | 2.0.0 ≤ 𝑥 < 2.1.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration