CVE-2020-35605
published 2020-12-21CVE-2020-35605: The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.61%
88.3th percentile
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | kitty | < kitty 0.19.3-1 (bookworm) | kitty 0.19.3-1 (bookworm) |
| kovidgoyal | kitty | < 0.19.3 | 0.19.3 |
| kovidgoyal | kitty | >= 0 < 0.19.3-1 | 0.19.3-1 |
| kovidgoyal | kitty | >= 0 < 0.19.3-1 | 0.19.3-1 |
| kovidgoyal | kitty | >= 0 < 0.19.3-1 | 0.19.3-1 |
| kovidgoyal | kitty | >= 0 < 0.19.3-1 | 0.19.3-1 |
| kovidgoyal | kitty | >= 0 < 0.15.0-1ubuntu0.2 | 0.15.0-1ubuntu0.2 |
| kovidgoyal | kitty | >= 0 < 0.21.2-1ubuntu0.22.04.1 | 0.21.2-1ubuntu0.22.04.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
kitty vulnerabilities
osv·2022-10-05·CVSS 9.8
CVE-2020-35605 [CRITICAL] kitty vulnerabilities
kitty vulnerabilities
Stephane Chauveau discovered that kitty incorrectly handled image
filenames with special characters in error messages. A remote
attacker could possibly use this to execute arbitrary commands.
This issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)
Carter Sande discovered that kitty incorrectly handled escape
sequences in desktop notifications. A remote attacker could possibly
use this to execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-41322)
GHSA
GHSA-6fm5-8wjh-r65x: The Graphics Protocol feature in graphics
ghsa_unreviewed·2022-05-24
CVE-2020-35605 [CRITICAL] GHSA-6fm5-8wjh-r65x: The Graphics Protocol feature in graphics
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
OSV
CVE-2020-35605: The Graphics Protocol feature in graphics
osv·2020-12-21·CVSS 9.8
CVE-2020-35605 [CRITICAL] CVE-2020-35605: The Graphics Protocol feature in graphics
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Ubuntu
kitty vulnerabilities
vendor_ubuntu·2022-10-05·CVSS 9.8
CVE-2022-41322 [CRITICAL] kitty vulnerabilities
Title: kitty vulnerabilities
Summary: kitty could be made to run programs if it opened a specially
crafted image or desktop notification.
Stephane Chauveau discovered that kitty incorrectly handled image
filenames with special characters in error messages. A remote
attacker could possibly use this to execute arbitrary commands.
This issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)
Carter Sande discovered that kitty incorrectly handled escape
sequences in desktop notifications. A remote attacker could possibly
use this to execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-41322)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-35605: kitty - The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote...
vendor_debian·2020·CVSS 9.8
CVE-2020-35605 [CRITICAL] CVE-2020-35605: kitty - The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote...
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Scope: local
bookworm: resolved (fixed in 0.19.3-1)
bullseye: resolved (fixed in 0.19.3-1)
forky: resolved (fixed in 0.19.3-1)
sid: resolved (fixed in 0.19.3-1)
trixie: resolved (fixed in 0.19.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kovidgoyal/kitty/commit/82c137878c2b99100a3cdc1c0f0efea069313901https://github.com/kovidgoyal/kitty/issues/3128https://www.debian.org/security/2020/dsa-4819https://github.com/kovidgoyal/kitty/commit/82c137878c2b99100a3cdc1c0f0efea069313901https://github.com/kovidgoyal/kitty/issues/3128https://www.debian.org/security/2020/dsa-4819
2020-12-21
Published