CVE-2014-2905
EPSS 0.04%
Description
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.
How to fix CVE-2014-2905
To remediate CVE-2014-2905, upgrade the affected package to a fixed version below.
- Debian/fish—upgrade to 2.1.1-1 or later
Is CVE-2014-2905 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.1-1