NVD Vulnerability Detail
Search Exploit, PoC
CVE-2023-49284
Summary

fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe internal representation. While this may cause unexpected behavior with direct input (for example, echo \UFDD2HOME has the same output as echo $HOME), this may become a minor security problem if the output is being fed from an external program into a command substitution where this output may not be expected. This design flaw was introduced in very early versions of fish, predating the version control system, and is thought to be present in every version of fish released in the last 15 years or more, although with different characters. Code execution does not appear to be possible, but denial of service (through large brace expansion) or information disclosure (such as variable expansion) is potentially possible under certain circumstances. fish shell 3.6.2 has been released to correct this issue. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Publication Date Dec. 5, 2023, 9:15 a.m.
Registration Date Dec. 5, 2023, noon
Last Update Nov. 21, 2024, 5:33 p.m.
CVSS3.1 : MEDIUM
スコア 6.6
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
攻撃元区分(AV) ローカル
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI)
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I) なし
可用性への影響(A)
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:fishshell:fish:*:*:*:*:*:*:*:* 3.6.2
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
fishshell の fish における解釈の競合に関する脆弱性
Title fishshell の fish における解釈の競合に関する脆弱性
Summary

fishshell の fish には、解釈の競合に関する脆弱性が存在します。

Possible impacts 情報を取得される、およびサービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。

Publication Date Dec. 5, 2023, midnight
Registration Date Jan. 12, 2024, 10:37 a.m.
Last Update Jan. 12, 2024, 10:37 a.m.
Affected System
fishshell
fish 3.6.2 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2024年01月12日]
  掲載
Jan. 12, 2024, 10:37 a.m.