CVE-2020-35605Kitty vulnerability

6 documents5 sources
Severity
9.8CRITICALNVD
EPSS
5.5%
top 9.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateOct 5

Description

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/kitty< kitty 0.19.3-1 (bookworm)
NVDkovidgoyal/kitty< 0.19.3
Debiankovidgoyal/kitty< 0.19.3-1+3
Ubuntukovidgoyal/kitty< 0.15.0-1ubuntu0.2+1

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

3
OSV
kitty vulnerabilities2022-10-05
GHSA
GHSA-6fm5-8wjh-r65x: The Graphics Protocol feature in graphics2022-05-24
OSV
CVE-2020-35605: The Graphics Protocol feature in graphics2020-12-21

📋Vendor Advisories

2
Ubuntu
kitty vulnerabilities2022-10-05
Debian
CVE-2020-35605: kitty - The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote...2020
CVE-2020-35605 — Kovidgoyal Kitty vulnerability | cvebase