Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.announce.security > #3773
| Path | csiph.com!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Salvatore Bonaccorso <carnil@debian.org> |
| Newsgroups | linux.debian.announce.security |
| Subject | [SECURITY] [DSA 5234-1] fish security update |
| Date | Wed, 21 Sep 2022 20:50:01 +0200 |
| Message-ID | <F8cXf-97XP-1@gated-at.bofh.it> (permalink) |
| X-Original-To | debian-security-announce@lists.debian.org |
| X-Mailbox-Line | From debian-security-announce-request@lists.debian.org Wed Sep 21 18:46:30 2022 |
| Old-Return-Path | <carnil@seger.debian.org> |
| X-Amavis-Spam-Status | No, score=-113.491 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_MED=-2.3, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no |
| Old-Dkim-Signature | v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=HQUNIXoodhy9zuhKP6lofMitzzPb3tD0kyiL7kXCyGM=; b=rx 7N0RNWqOfVr593GdtG6HEJ2oQxrBM5j6JsX6xSVM6Nu1aiXgrtC2aBA/XIo4gLuulUUe8w+71ehry G2NZx7hbLS+v/l2cHlCETOEo/QVOrlV2dYB1vvoIIRoLjyRfX/mheA3CVIZgK8TpPFJLrQmRyLKqh cbyfEFaIfKsa3trRkOOH2URHEK2wZTTHKCEk8EXA8JmB5Ih4buhGTCjVHDUMj2P56OzzrQO9+23z8 EhoGQSfJRoFx5mNAp56UIEIjCir5JEJjIPmNeIRrs5HnffEiReclPA/sjUXG80GI8YUyC4zdf2l6A fw4Ei2hYf65dw050fL7O0iGLVT0Lymvw==; |
| X-Debian | PGP check passed for security officers |
| Priority | urgent |
| Reply-To | debian-security-announce-request@lists.debian.org |
| X-Mailing-List | <debian-security-announce@lists.debian.org> archive/latest/4132 |
| List-ID | <debian-security-announce.lists.debian.org> |
| List-URL | <http://lists.debian.org/debian-security-announce/> |
| List-Archive | https://lists.debian.org/msgid-search/E1ob4jP-00DBwr-B6@seger.debian.org |
| Approved | robomod@news.nic.it |
| Lines | 51 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Wed, 21 Sep 2022 18:45:59 +0000 |
| X-Original-Message-ID | <E1ob4jP-00DBwr-B6@seger.debian.org> |
| Xref | csiph.com linux.debian.announce.security:3773 |
Show key headers only | View raw
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5234-1 security@debian.org https://www.debian.org/security/ Aron Xu September 21, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : fish CVE ID : CVE-2022-20001 An arbitrary code execution vulnerability was disovered in fish, a command line shell. When using the default configuraton of fish, changing to a directory automatically ran `git` commands in order to display information about the current repository in the prompt. Such repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. For the stable distribution (bullseye), this problem has been fixed in version 3.1.2-3+deb11u1. We recommend that you upgrade your fish packages. For the detailed security status of fish please refer to its security tracker page at: https://security-tracker.debian.org/tracker/fish Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmMrW8pfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Rrlg/9FWqWYkhEI1NHuxbo4DNcsWg6j29LwdrTnLZpBm/eIuV0uzeEVK53hPu0 COm76y3am/p+HVB5+JS5AMJ50Crjg6Ey2HgK+l9uaJh2lrXVpy87vGW/AehAX+DN owZJrjbBHYcDaK4P179Wuic7V/WQnf8majq7OeCtCLNia2dIIgsQQ8smt2UXYSYg inCgTMoVG8fjNE8MN9ntw/FP+B1zA1o6YG8S1LvRPGS8KZzEuv6HjYzZ/smGx5W0 pk8wY6KnbGBnb1VtJYhvnXNoYGh/riCLLQ5ASD/jZi+qLZsu+7OHFm+CTsITc/p4 Ln/Pfxmp3+FSjQ0SOpt1GJI9UHz0qOdMEc4/mvowkkZFT4emar3sgN1qfCxtH/HP p566fc/ShwANJ3Y+sVwr8isy17at3exBdrSQowZUT3YRfhpU6Xen6eZIu2sJQzON WKji6Cy3JNi+CVTi/RZnGBjxpX0mLv0GffzRZmENbcYt7uCMhbrsXno0pghpST2P i3yBvI1VWL9FjOGMHzVov4vh6DysaDwQowWux2sEYCNSxsxs9KIWlBE9iiKWk0fI +A1avvjnnaPaOrb+HsvuMYE+xgJigwcEJB9B+TonhnB+TlPaQM0IWeSM6Rty05U5 GPvbG547s31r+RJkmvcI5c0HUc3XPRNdt5XKv56sd6/9zI2hczc= =2RGj -----END PGP SIGNATURE-----
Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread
[SECURITY] [DSA 5234-1] fish security update Salvatore Bonaccorso <carnil@debian.org> - 2022-09-21 20:50 +0200
csiph-web