CVE-2014-3219: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Affected products
- Fedoraproject Fedora: version 19 only
- Fishshell Fish: before 2.1.1 (fixed in 2.1.1)
Published 2018-02-09. Last modified 2026-06-17.