Описание
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (исключая)
cpe:2.3:a:appimage:appimaged:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00089
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-494
Связанные уязвимости
CVSS3: 5.5
ubuntu
около 5 лет назад
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.
github
больше 3 лет назад
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.
EPSS
Процентиль: 25%
0.00089
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-494