Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.announce.security > #3773

[SECURITY] [DSA 5234-1] fish security update

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.announce.security
Subject [SECURITY] [DSA 5234-1] fish security update
Date Wed, 21 Sep 2022 20:50:01 +0200
Message-ID <F8cXf-97XP-1@gated-at.bofh.it> (permalink)
X-Original-To debian-security-announce@lists.debian.org
X-Mailbox-Line From debian-security-announce-request@lists.debian.org Wed Sep 21 18:46:30 2022
Old-Return-Path <carnil@seger.debian.org>
X-Amavis-Spam-Status No, score=-113.491 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_MED=-2.3, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no
Old-Dkim-Signature v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=HQUNIXoodhy9zuhKP6lofMitzzPb3tD0kyiL7kXCyGM=; b=rx 7N0RNWqOfVr593GdtG6HEJ2oQxrBM5j6JsX6xSVM6Nu1aiXgrtC2aBA/XIo4gLuulUUe8w+71ehry G2NZx7hbLS+v/l2cHlCETOEo/QVOrlV2dYB1vvoIIRoLjyRfX/mheA3CVIZgK8TpPFJLrQmRyLKqh cbyfEFaIfKsa3trRkOOH2URHEK2wZTTHKCEk8EXA8JmB5Ih4buhGTCjVHDUMj2P56OzzrQO9+23z8 EhoGQSfJRoFx5mNAp56UIEIjCir5JEJjIPmNeIRrs5HnffEiReclPA/sjUXG80GI8YUyC4zdf2l6A fw4Ei2hYf65dw050fL7O0iGLVT0Lymvw==;
X-Debian PGP check passed for security officers
Priority urgent
Reply-To debian-security-announce-request@lists.debian.org
X-Mailing-List <debian-security-announce@lists.debian.org> archive/latest/4132
List-ID <debian-security-announce.lists.debian.org>
List-URL <http://lists.debian.org/debian-security-announce/>
List-Archive https://lists.debian.org/msgid-search/E1ob4jP-00DBwr-B6@seger.debian.org
Approved robomod@news.nic.it
Lines 51
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 21 Sep 2022 18:45:59 +0000
X-Original-Message-ID <E1ob4jP-00DBwr-B6@seger.debian.org>
Xref csiph.com linux.debian.announce.security:3773

Show key headers only | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5234-1                   security@debian.org
https://www.debian.org/security/                                  Aron Xu
September 21, 2022                    https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : fish
CVE ID         : CVE-2022-20001

An arbitrary code execution vulnerability was disovered in fish, a
command line shell. When using the default configuraton of fish,
changing to a directory automatically ran `git` commands in order to
display information about the current repository in the prompt. Such
repositories can contain per-repository configuration that change the
behavior of git, including running arbitrary commands.

For the stable distribution (bullseye), this problem has been fixed in
version 3.1.2-3+deb11u1.

We recommend that you upgrade your fish packages.

For the detailed security status of fish please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/fish

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmMrW8pfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Rrlg/9FWqWYkhEI1NHuxbo4DNcsWg6j29LwdrTnLZpBm/eIuV0uzeEVK53hPu0
COm76y3am/p+HVB5+JS5AMJ50Crjg6Ey2HgK+l9uaJh2lrXVpy87vGW/AehAX+DN
owZJrjbBHYcDaK4P179Wuic7V/WQnf8majq7OeCtCLNia2dIIgsQQ8smt2UXYSYg
inCgTMoVG8fjNE8MN9ntw/FP+B1zA1o6YG8S1LvRPGS8KZzEuv6HjYzZ/smGx5W0
pk8wY6KnbGBnb1VtJYhvnXNoYGh/riCLLQ5ASD/jZi+qLZsu+7OHFm+CTsITc/p4
Ln/Pfxmp3+FSjQ0SOpt1GJI9UHz0qOdMEc4/mvowkkZFT4emar3sgN1qfCxtH/HP
p566fc/ShwANJ3Y+sVwr8isy17at3exBdrSQowZUT3YRfhpU6Xen6eZIu2sJQzON
WKji6Cy3JNi+CVTi/RZnGBjxpX0mLv0GffzRZmENbcYt7uCMhbrsXno0pghpST2P
i3yBvI1VWL9FjOGMHzVov4vh6DysaDwQowWux2sEYCNSxsxs9KIWlBE9iiKWk0fI
+A1avvjnnaPaOrb+HsvuMYE+xgJigwcEJB9B+TonhnB+TlPaQM0IWeSM6Rty05U5
GPvbG547s31r+RJkmvcI5c0HUc3XPRNdt5XKv56sd6/9zI2hczc=
=2RGj
-----END PGP SIGNATURE-----

Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread


Thread

[SECURITY] [DSA 5234-1] fish security update Salvatore Bonaccorso <carnil@debian.org> - 2022-09-21 20:50 +0200

csiph-web