CVE-2020-35605

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2020
Last modified:
24/04/2025

Description

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:* 0.19.3 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*