From ca2977e80c0b29d0e6ce6ff178b6e0043442262b Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 29 Sep 2023 17:37:53 +0100 Subject: gentoo auto-resync : 29:09:2023 - 17:37:53 --- metadata/glsa/glsa-202309-10.xml | 42 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 metadata/glsa/glsa-202309-10.xml (limited to 'metadata/glsa/glsa-202309-10.xml') diff --git a/metadata/glsa/glsa-202309-10.xml b/metadata/glsa/glsa-202309-10.xml new file mode 100644 index 000000000000..ab90f225c850 --- /dev/null +++ b/metadata/glsa/glsa-202309-10.xml @@ -0,0 +1,42 @@ + + + + Fish: User-assisted execution of arbitrary code + A vulnerability was discovered in Fish when handling git repository configuration that may lead to execution of arbitrary code + fish + 2023-09-29 + 2023-09-29 + 835337 + local + + + 3.4.0 + 3.4.0 + + + +

Smart and user-friendly command line shell for macOS, Linux, and the rest of the family. It includes features like syntax highlighting, autosuggest-as-you-type, and fancy tab completions that just work, with no configuration required.

+
+ +

A vulnerability have been discovered in Fish. Please review the CVE identifiers referenced below for details.

+
+ +

A user may be enticed to cd into a git repository under control by an attacker (e.g. on a shared filesystem or by unpacking an archive) and execute arbitrary commands.

+
+ +

There is no known workaround at this time.

+
+ +

All fish users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-shells/fish-3.4.0" + +
+ + CVE-2022-20001 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3