Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2022-0364 Critical: Kitty Notification Escape Execution

mageia
Calendar Grey October 8, 2022
Dist Mageia Esm H88
The latest kitty updates in Mageia address a vulnerability concerning notification escape that could allow malicious code execution.
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution

Summary

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. (CVE-2022-41322)

References

- https://bugs.mageia.org/show_bug.cgi?id=30930

- https://nvd.nist.gov/vuln/detail/CVE-2022-41322

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI/

- https://sw.kovidgoyal.net/kitty/changelog/#id2

- https://www.cve.org/CVERecord?id=CVE-2022-41322

Resolution

SRPMS

- 8/core/kitty-0.26.3-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0364.html
Type: security
CVE: CVE-2022-41322

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here