Описание
AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libappimage | fixed | 1.0.4-1 | package | |
| libappimage | no-dsa | buster | package |
Примечания
https://github.com/AppImage/libappimage/pull/146
https://github.com/refi64/CVE-2020-25265-25266
https://github.com/AppImageCommunity/libappimage/pull/146
Связанные уязвимости
AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.
AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.
AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.