CVE-2020-35605 - log back

CVE-2020-35605 edited at 21 Dec 2020 21:53:35
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary command execution
Description
+ The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
References
+ https://github.com/kovidgoyal/kitty/issues/3128
+ https://github.com/kovidgoyal/kitty/commit/82c137878c2b99100a3cdc1c0f0efea069313901
Notes
CVE-2020-35605 created at 21 Dec 2020 21:51:56