Debian alert DLA-4203-1 (kitty)
| From: | Tobias Frost <tobi@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4203-1] kitty security update | |
| Date: | Sun, 01 Jun 2025 11:27:16 +0200 | |
| Message-ID: | <aDwc9Jqjkck2-NOK@isildor2.loewenhoehle.ip> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4203-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost June 01, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : kitty Version : 0.19.3-1+deb11u1 CVE ID : CVE-2022-41322 Debian Bug : 1020582 A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322 In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. For Debian 11 bullseye, this problem has been fixed in version 0.19.3-1+deb11u1. We recommend that you upgrade your kitty packages. For the detailed security status of kitty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kitty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAmg8HPAACgkQkWT6HRe9 XTZMgA//eVMwnxLWEgQOcQgl8ebKJSYA33o0Y6vHsQoXHDWVDNoe/Mxh8YyQdrer ezjuT7D/2AJM06EADW/wtQ+ePcHfVZzx8lwdU5j+0zx/lcVLYqsebEUlEqngL8Tk KRVL2tvpoV5scMrVj8W8WeS4OnDX+CQv05PpD69plx72M96TLx1IRIwqWNkE5cfL Rirk7BGp65sHHRwKMe+0WY3zJPORFhGl9Tx9RQ3jqlt69Nu2n9lEmJ+2PL+pdpmm pMAbZSRYv5j5oAFiyjcgxR7xvuokNgTV/7yAB51z9a6CFx8VV8YGOzgbjyQJZ9LP xMOPKZqWeH3UMHm65hdW3GBlTtKmglhFAIhNcEz81rWg9mpxn3Cx2LeYgEikjDqK rFtdr2f2ZSkE1M8GKYcXxo3tnMLG/D/57t1p74kEW9hRuycC1IxLvf3aJBlR4SkH 7aSf6b3kOMzGg9E3fr6w3vVqv5r86Ju4V2iruwf8flyXvEDC4Rh/p+ficVPzDnra lFLhLbmxoo1whCPMJ1Fo6jZsHZ41thGg1as596UB4ySoPGUGd26uKZKfy2N1bpIO 0bLztMFV6FIVZCilk26yAJsaVzT6z3mnD2qNkPMSwLYfj7QAGggiNHxwZp5ef2x5 5vKHPzKb2wzv0LXVkTn5TNHXkEPrnC59LY9KbvKetIIPA4qcgPY= =xO4h -----END PGP SIGNATURE-----
