From c6ee8892052cc41b32dd714edc0f366bff3b60ee Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Fri, 29 Sep 2023 10:53:28 +0000 Subject: [ GLSA 202309-10 ] Fish: User-assisted execution of arbitrary code Bug: https://bugs.gentoo.org/835337 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202309-10.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202309-10.xml (limited to 'glsa-202309-10.xml') diff --git a/glsa-202309-10.xml b/glsa-202309-10.xml new file mode 100644 index 00000000..ab90f225 --- /dev/null +++ b/glsa-202309-10.xml @@ -0,0 +1,42 @@ + + + + Fish: User-assisted execution of arbitrary code + A vulnerability was discovered in Fish when handling git repository configuration that may lead to execution of arbitrary code + fish + 2023-09-29 + 2023-09-29 + 835337 + local + + + 3.4.0 + 3.4.0 + + + +

Smart and user-friendly command line shell for macOS, Linux, and the rest of the family. It includes features like syntax highlighting, autosuggest-as-you-type, and fancy tab completions that just work, with no configuration required.

+
+ +

A vulnerability have been discovered in Fish. Please review the CVE identifiers referenced below for details.

+
+ +

A user may be enticed to cd into a git repository under control by an attacker (e.g. on a shared filesystem or by unpacking an archive) and execute arbitrary commands.

+
+ +

There is no known workaround at this time.

+
+ +

All fish users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-shells/fish-3.4.0" + +
+ + CVE-2022-20001 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad