High severity7.0NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026
CVE-2014-3856
CVE-2014-3856
Description
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- fish/fish-shelldescription
- Range: <2.1.1
- osv-coords3 versionspkg:rpm/opensuse/fish&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/fish3&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/fish3&distro=openSUSE%20Leap%2015.1
< 2.4.0-1.1+ 2 more
- (no CPE)range: < 2.4.0-1.1
- (no CPE)range: < 3.0.0-lp150.3.1
- (no CPE)range: < 3.0.0-lp151.2.1
Patches
Vulnerability mechanics
References
3- github.com/fish-shell/fish-shell/issues/1437nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2014/04/28/4nvdMailing ListThird Party Advisory
- github.com/fish-shell/fish-shell/releases/tag/2.1.1nvdRelease Notes
News mentions
0No linked articles in our index yet.