CVE-2014-2905
EPSS 0.04%發布日:2014/5/2修改日:2026/4/28
也稱為:DEBIAN-CVE-2014-2905
描述
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.
受影響套件(1)
- Debian/fishfrom 0, < 2.1.1-1