View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2014-2906 severity important: SUSE including 8 source package names (fish-2.2.0-6.1, fish-2.4.0-1.1, …), 8 product×package rows across 5 product lines (SUSE Linux Enterprise Server 16.0, SUSE Package Hub 12, … (5 product lines)): Fixed 8.
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.