Описание
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | ignored | superseded by openjdk-17 |
| focal | ignored | end of standard support, was ignored [superseded by openjdk-17] |
| jammy | DNE | |
| noble | DNE | |
| oracular | DNE | |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | ignored | superseded by openjdk-17 |
| focal | ignored | end of standard support, was ignored [superseded by openjdk-17] |
| jammy | DNE | |
| noble | DNE | |
| oracular | DNE | |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see note |
| esm-apps/bionic | not-affected | see note |
| esm-apps/jammy | not-affected | see note |
| focal | not-affected | see note |
| jammy | not-affected | see note |
| noble | not-affected | see note |
| oracular | not-affected | see note |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | ignored | superseded by openjdk-19 |
| noble | DNE | |
| oracular | DNE | |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| oracular | DNE | |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see note |
| focal | not-affected | see note |
| jammy | not-affected | see note |
| noble | not-affected | see note |
| oracular | not-affected | see note |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| oracular | not-affected | see note |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see note |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| oracular | not-affected | see note |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see note |
| esm-apps/bionic | not-affected | see note |
| esm-apps/focal | not-affected | see note |
| esm-apps/jammy | not-affected | see note |
| esm-apps/noble | not-affected | see note |
| esm-infra/xenial | not-affected | see note |
| focal | not-affected | see note |
| jammy | not-affected | see note |
| noble | not-affected | see note |
| oracular | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/xenial | ignored | no longer supported by upstream |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| oracular | DNE | |
| upstream | not-affected | see note |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | see note |
| esm-apps/noble | not-affected | see note |
| esm-infra/bionic | not-affected | see note |
| esm-infra/focal | not-affected | see note |
| focal | not-affected | see note |
| jammy | not-affected | see note |
| noble | not-affected | see note |
| oracular | not-affected | see note |
| upstream | not-affected | see note |
Показывать по
Ссылки на источники
7.3 High
CVSS3
Связанные уязвимости
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
A security issue was found in Sparkle before version 2.6.4. An attacke ...
Уязвимость фреймворка Sparkle программной платформы Oracle Java SE, связанная с раскрытием файлов или каталогов внешним сторонам, позволяющая нарушителю обойти проверку подписи (Ed)DSA и получить полный контроль над приложением
7.3 High
CVSS3