Fish-shell '/tmp/fishd.socket.user' Local Privilege Escalation Vulnerability
BID:67097
Info
Fish-shell '/tmp/fishd.socket.user' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 67097 |
| Class: | Design Error |
| CVE: |
CVE-2014-2905 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 27 2014 12:00AM |
| Updated: | Apr 13 2015 08:26PM |
| Credit: | David Adam |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Exploit / POC
Fish-shell '/tmp/fishd.socket.user' Local Privilege Escalation Vulnerability
Local attackers can use readily available tools to exploit this issue.
Local attackers can use readily available tools to exploit this issue.
Solution / Fix
Fish-shell '/tmp/fishd.socket.user' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Fish-shell '/tmp/fishd.socket.user' Local Privilege Escalation Vulnerability
References:
References:
- /tmp/fishd.socket.user permissions checking (CVE-2014-2905) #1436 (Fishshell)
- Fishshell homepage (Fishshell)