CVE-2020-26292 Information
Jun 07, 2022
cve
Description
Creeper is an experimental dynamic interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours between December 26 2020 at 3:22 PM EST to December 26 2020 at 11:00 PM EST. If you used the source code you are NOT affected. This only affects the binary releases. The binary of unknown quality has been removed from the release. If you have downloaded the binary please delete it and run a reputable antivirus scanner to ensure that your computer is clean.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/chatter-social/Creeper/security/advisories/GHSA-9v67-g2rg-m33j
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: