Release date:
Updated on:
Affected Systems:
Fish-shell 1.16.0-2.1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67095
CVE (CAN) ID: CVE-2014-2914
Fish is a Unix shell. Provides user-friendly and powerful command line completion, including descriptions of each completion item, tab completion of strings containing wildcards, and completion of many specific commands.
Fish-shell 1.16.0-2.1.0 has a remote code execution vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
<* Source: David Adam
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Fish-shell
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://fishshell.com/