Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-0509

Опубликовано: 04 фев. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.3

Описание

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
focal

ignored

end of standard support, was ignored [superseded by openjdk-17]
jammy

DNE

noble

DNE

oracular

DNE

upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

ignored

superseded by openjdk-17
focal

ignored

end of standard support, was ignored [superseded by openjdk-17]
jammy

DNE

noble

DNE

oracular

DNE

upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-apps/bionic

not-affected

see note
esm-apps/jammy

not-affected

see note
focal

not-affected

see note
jammy

not-affected

see note
noble

not-affected

see note
oracular

not-affected

see note
upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by openjdk-19
noble

DNE

oracular

DNE

upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

ignored

no longer supported by upstream
noble

DNE

oracular

DNE

upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
focal

not-affected

see note
jammy

not-affected

see note
noble

not-affected

see note
oracular

not-affected

see note
upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

not-affected

see note
upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

not-affected

see note
upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-apps/bionic

not-affected

see note
esm-apps/focal

not-affected

see note
esm-apps/jammy

not-affected

see note
esm-apps/noble

not-affected

see note
esm-infra/xenial

not-affected

see note
focal

not-affected

see note
jammy

not-affected

see note
noble

not-affected

see note
oracular

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

ignored

no longer supported by upstream
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

upstream

not-affected

see note

Показывать по

РелизСтатусПримечание
devel

not-affected

see note
esm-apps/noble

not-affected

see note
esm-infra/bionic

not-affected

see note
esm-infra/focal

not-affected

see note
focal

not-affected

see note
jammy

not-affected

see note
noble

not-affected

see note
oracular

not-affected

see note
upstream

not-affected

see note

Показывать по

Ссылки на источники

EPSS

Процентиль: 1%
0.00013
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
7 месяцев назад

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.

CVSS3: 7.3
debian
7 месяцев назад

A security issue was found in Sparkle before version 2.6.4. An attacke ...

CVSS3: 7.3
github
7 месяцев назад

Sparkle Signing Checks Bypass

CVSS3: 7.3
fstec
больше 1 года назад

Уязвимость фреймворка Sparkle программной платформы Oracle Java SE, связанная с раскрытием файлов или каталогов внешним сторонам, позволяющая нарушителю обойти проверку подписи (Ed)DSA и получить полный контроль над приложением

EPSS

Процентиль: 1%
0.00013
Низкий

7.3 High

CVSS3