MGASA-2023-0344

Source
https://advisories.mageia.org/MGASA-2023-0344.html
Import Source
https://advisories.mageia.org/MGASA-2023-0344.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0344
Related
Published
2023-12-12T21:19:08Z
Modified
2023-12-12T19:32:52Z
Summary
Updated fish packages fix a security vulnerability
Details

Mageia 9 is updated to version 3.6.4 to fix CVE-2023-49284. Mageia 8 receives an upstream patch to fix CVE-2023-49284. CVE-2023-49284: fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe internal representation.

References
Credits

Affected packages

Mageia:9 / fish

Package

Name
fish
Purl
pkg:rpm/mageia/fish?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.4-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / fish

Package

Name
fish
Purl
pkg:rpm/mageia/fish?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.1-1.1.mga8

Ecosystem specific

{
    "section": "core"
}