{"id":"MGASA-2023-0344","summary":"Updated fish packages fix a security vulnerability","details":"Mageia 9 is updated to version 3.6.4 to fix CVE-2023-49284.\nMageia 8 receives an upstream patch to fix CVE-2023-49284.\nCVE-2023-49284: fish shell uses certain Unicode non-characters\ninternally for marking wildcards and expansions. It will incorrectly\nallow these markers to be read on command substitution output, rather\nthan transforming them into a safe internal representation.\n","modified":"2026-04-16T00:12:19.917323187Z","published":"2023-12-12T21:19:08Z","upstream":["CVE-2023-49284"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0344.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32614"}],"affected":[{"package":{"name":"fish","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/fish?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.1-1.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0344.json"}},{"package":{"name":"fish","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/fish?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.4-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0344.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}