摘要:
A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
安全等级: Low
公告ID: KylinSec-SA-2025-1112
发布日期: 2025年2月17日
关联CVE: CVE-2025-0509
A security issue was found in Sparkle before version 2.64. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2025-0509 | KY3.4-5A | openjdk-11 | Unaffected |
CVE-2025-0509 | V6 | openjdk-11 | Unaffected |