Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: haskellPackages.PenroseKiteDart

Found 1 matching suggestions

View:
Compact
Detailed
Permalink CVE-2020-36958
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months ago
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path

Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.

Affected products

Kite
  • =<1.2020.1119.0

Matching in nixpkgs

pkgs.kitex

A high-performance and strong-extensibility Golang RPC framework