Fish-shell 'funced' Function Insecure Temporary File Creation Vulnerability
BID:67605
Info
Fish-shell 'funced' Function Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 67605 |
| Class: | Design Error |
| CVE: |
CVE-2014-3856 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 28 2014 12:00AM |
| Updated: | Apr 13 2015 09:48PM |
| Credit: | David Adam |
| Vulnerable: |
Fishshell Fish-shell 1.23 Fishshell Fish-shell 2.1.0 Fishshell Fish-shell 2.0.0 |
| Not Vulnerable: |
Fishshell Fish-shell 2.1.1 |
Discussion
Fish-shell 'funced' Function Insecure Temporary File Creation Vulnerability
Fish-shell is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to gain elevated privileges.
Fish-shell versions 1.23.0 through 2.1.0 are vulnerable.
NOTE: This issue was previously covered in BID 67098 but has been given its own record for better documentation.
Fish-shell is prone to an insecure temporary file-creation vulnerability.
An attacker with local access could potentially exploit this issue to gain elevated privileges.
Fish-shell versions 1.23.0 through 2.1.0 are vulnerable.
NOTE: This issue was previously covered in BID 67098 but has been given its own record for better documentation.
References
Fish-shell 'funced' Function Insecure Temporary File Creation Vulnerability
References:
References:
- psub and funced don't protect tempfiles (CVE-2014-2906) #1437 (Fish-Shell)
- Fishshell homepage (Fishshell)