VDB

GCVE-110-MAGEIA-2023-344

GCVE-110-MAGEIA-2023-344
Advisory Published
Vulnetix · Advisory published December 12, 2023
Mageia 9 is updated to version 3.6.4 to fix CVE-2023-49284. Mageia 8 receives an upstream patch to fix CVE-2023-49284. CVE-2023-49284: fish shell uses certain Unicode non-characters internally for marking wildcards and expansions. It will incorrectly allow these markers to be read on command substitution output, rather than transforming them into a safe internal representation.

Affected Products

VendorProductVersionsPlatforms
Mageiafish0 (affected), 3.6.4-1.mga9 (unaffected)
Mageiafish0 (affected), 3.4.1-1.1.mga8 (unaffected)

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›