Bug#1020582: kitty: CVE-2022-41322

2022-09-28 Thread James McCoy
On Fri, Sep 23, 2022 at 08:38:27PM +0200, Salvatore Bonaccorso wrote: > CVE-2022-41322[0]: > | In Kitty before 0.26.2, insufficient validation in the desktop > | notification escape sequence can lead to arbitrary code execution. The > | user must display attacker-controlled content in the terminal,

Bug#1020582: kitty: CVE-2022-41322

2022-09-23 Thread Salvatore Bonaccorso
Source: kitty Version: 0.21.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for kitty. CVE-2022-41322[0]: | In Kitty before 0.26.2, insufficient validation in the desktop | notification escape se