CVE-2020-25266

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/12/2020
Last modified:
07/12/2020

Description

AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:appimage:appimaged:*:*:*:*:*:*:*:* 1.0.3 (excluding)


References to Advisories, Solutions, and Tools