CVE-2020-35605: Critical severity kitty vulnerability
Published Dec 21, 2020
·Updated
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Affected Software
4 affected componentsFixes available
debian/kitty
0.13.3-1+deb10u10.19.3-10.26.5-5
Kitty Project Kitty<0.19.3
Debian Debian Linux=10.0
Kovidgoyal Kitty<0.19.3
Remediation
Event History
Dec 21, 2020
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35605?
CVE-2020-35605 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2020-35605?
To fix CVE-2020-35605, upgrade to kitty version 0.19.3 or later.
3
What software is affected by CVE-2020-35605?
CVE-2020-35605 affects kitty versions prior to 0.19.3, particularly in Debian distributions.
4
Can CVE-2020-35605 be exploited remotely?
Yes, CVE-2020-35605 can be exploited remotely through specially crafted filenames in error messages.
5
What are the potential consequences of CVE-2020-35605?
The exploitation of CVE-2020-35605 can lead to arbitrary code execution, compromising the affected system.