AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libappimage | Appimage | * | 1.0.3 (excluding) |
Libappimage | Ubuntu | groovy | * |
Libappimage | Ubuntu | hirsute | * |
Libappimage | Ubuntu | impish | * |
Libappimage | Ubuntu | kinetic | * |
Libappimage | Ubuntu | lunar | * |
Libappimage | Ubuntu | mantic | * |
Libappimage | Ubuntu | trusty | * |