The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade utilities/kate
to version 21.12.2 or higher.
Affected versions of this package are vulnerable to Untrusted Search Path due to the way the application searches for executable files. Both KTextEditor and KDE Kate try to execute binaries (Kate - 'git', 'svn', and LSP binaries. KTextEditor - 'git') when opening a file of a given type. If this binary is absent from the PATH environment variable, it will try running the binary in the directory of the file that was just opened. This allows a local user to place a malicious binary file into a current working directory, run the application, and in turn the application will run his file with elevated privileges.