Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Gentoo: GLSA-202209-22 Normal: Kitty Arbitrary Code Execution Risk

gentoo
Calendar Grey September 29, 2022
Dist Gentoo Esm H88
A weakness in Kitty permits unauthorized command execution through crafted input. Users on Gentoo advised to update.
A vulnerability has been found in Kitty which could allow for arbitrary code execution with user input.

Summary

Carter Sande discovered that maliciously constructed control sequences can cause Kitty to display a notification that, when clicked, can cause Kitty to execute arbitrary commands.

Resolution

All Kitty users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=x11-terms/kitty-0.26.2"

References

[ 1 ] CVE-2022-41322 https://nvd.nist.gov/vuln/detail/CVE-2022-41322

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202209-22
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: Normal
Title: Kitty: Arbitrary Code Execution
Date: September 29, 2022
Bugs: #868543
ID: 202209-22

Synopsis

A vulnerability has been found in Kitty which could allow for arbitrary code execution with user input.

Background

Kitty is a fast, feature-rich, GPU-based terminal.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-terms/kitty < 0.26.2 >= 0.26.2

Impact

===== Kitty can produce notifications that, when clicked, can execute arbitrary commands.

Workaround

Avoid clicking unexpected notifications.

Your message here