CVE-2025-0509

Publication date

2025-02-04 20:01:08

Family

fedora

State

PUBLISHED

Description

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.