Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2014-2905

Disclosure Date: May 02, 2014
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

General Information

Technical Analysis