PT-2024-3871 · Kitty · Kitty
Austin A. Defrancesco
+1
·
Published
2024-01-08
·
Updated
2024-02-15
·
CVE-2024-23749
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
KiTTY versions 0.76.1.13 and before
Description:
The issue is related to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls. This allows an attacker to add inputs inside the
filename variable, leading to arbitrary code execution. The vulnerability occurs due to the lack of proper data cleaning at the management level.Recommendations:
For KiTTY versions 0.76.1.13 and before, consider disabling the use of the
filename variable until a patch is available to prevent command injection attacks. Restrict access to the system calls at lines 2369-2390 to minimize the risk of exploitation. Avoid using special characters in the filename variable to reduce the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitty